Cross-Site Scripting Flaw in Computer Associates eTrust SiteMinder
CVE-2005-2204

Currently unrated

Key Information:

Vendor

Broadcom

Vendor
CVE Published:
11 July 2005

What is CVE-2005-2204?

A cross-site scripting (XSS) vulnerability exists in Computer Associates eTrust SiteMinder 5.5 when the 'CSSChecking' parameter is configured to 'NO'. This flaw enables remote attackers to execute arbitrary web scripts or HTML by injecting malicious code through certain parameters, such as PASSWORD, BUFFER, and TARGET parameters. This vulnerability poses a significant threat as it allows potential attackers to manipulate the web application's behavior and access sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2005-2204 : Cross-Site Scripting Flaw in Computer Associates eTrust SiteMinder