Netegrity SiteMinder输入验证漏洞

漏洞信息详情

Netegrity SiteMinder输入验证漏洞

漏洞简介

Netegrity SiteMinder 3.6到4.5.1版本存在漏洞。远程攻击者可以借助包含Unicode字符的URLs绕过过滤器。

漏洞公告

This issue is reportedly not present in Netegrity SiteMinder versions 4.5.1 SP1 and later.
It has been reported but not confirmed that the vendor has released a patch for earlier versions. Users should contact the vendor for details regarding the availability of fixes.

参考网址

来源:US-CERT Vulnerability Note: VU#837419
名称: VU#837419
链接:http://www.kb.cert.org/vuls/id/837419

来源: XF
名称: siteminder-unicode-bypass(10497)
链接:http://xforce.iss.net/xforce/xfdb/10497

来源: BID
名称: 6060
链接:http://www.securityfocus.com/bid/6060

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享