CVE-2008-1470
24.03.2008, 22:44
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.
Vendor | Product | Version |
---|---|---|
rsa | webid | 5.3 |
𝑥
= Vulnerable software versions