Cross-Site Scripting Flaw in Computer Associates eTrust SiteMinder
CVE-2005-2204
Currently unrated
What is CVE-2005-2204?
A cross-site scripting (XSS) vulnerability exists in Computer Associates eTrust SiteMinder 5.5 when the 'CSSChecking' parameter is configured to 'NO'. This flaw enables remote attackers to execute arbitrary web scripts or HTML by injecting malicious code through certain parameters, such as PASSWORD, BUFFER, and TARGET parameters. This vulnerability poses a significant threat as it allows potential attackers to manipulate the web application's behavior and access sensitive information.
References
Timeline
Vulnerability published
Vulnerability Reserved