Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17989
HistorySep 13, 2007 - 12:00 a.m.

RSA EnVision Reflected XSS Hole

2007-09-1300:00:00
vulners.com
22

#########################################
Application: RSA EnVision
Vendor: http://www.rsa.com
Version: Version 3.3.6 Build 0115
Bug: Cross-Site Scripting
Risk: Medium
Date: 12 Sept 2007
Author: Stelios Tigkas
e-mail: Stigkas at Gmail dot com
Current Employer: Fujitsu Services
List: BugTraq(SecurityFocus)
#########################################

=======
Product

A Security Event Management Solution.

===
Bug

There is a Reflected (Type I) Cross-Site Scripting hole on the
username field, in the logon page of the EnVision application. The
following attack vector has been confirmed by the Vendor to work:
</script><script>alert(document.cookie)</script>.

RSA have been notified on 23.03.2007