Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-08-05 21:00
Updated : 2017-07-10 18:30
NVD link : CVE-2004-0672
Mitre link : CVE-2004-0672
JSON object : View
CWE
Products Affected
netegrity
- identityminder
- policy_server