Cross-Site Scripting Vulnerability in Microsoft Forefront Unified Access Gateway
CVE-2010-3936
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 November 2010
What is CVE-2010-3936?
The vulnerability in Signurl.asp of Microsoft Forefront Unified Access Gateway (UAG) enables remote attackers to execute arbitrary web scripts or HTML code. This occurs through several unspecified vectors, which could be leveraged to perform attacks like session hijacking or redirecting users to malicious websites. Users and administrators are encouraged to apply the patch provided in the MS10-089 advisory to mitigate this security risk.