Cross-Site Scripting Vulnerabilities in Shibboleth by Internet2 Middleware Initiative
CVE-2009-3300

Currently unrated

Key Information:

Vendor

Internet2

Vendor
CVE Published:
6 November 2009

What is CVE-2009-3300?

Shibboleth by Internet2 Middleware Initiative contains multiple vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML. These vulnerabilities stem from improper handling of URLs encountered in redirections and appear in automatically generated forms. Attackers can exploit these weaknesses to execute malicious scripts within the user's browser, potentially compromising sensitive information and user interactions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.