CVE-2004-0672

Netegrity IdentityMinder Web Edition 5.6 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-0672. PoCs published by [email protected].

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Netegrity IdentityMinder by crafting a malicious URL that injects JavaScript code into the application's web interface. The vulnerability arises from insufficient input sanitization of URI parameters, allowing arbitrary script execution in the context of the victim's browser.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by [email protected] · textwebappscgi
https://www.exploit-db.com/exploits/24244

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Netegrity IdentityMinder by crafting a malicious URL that injects JavaScript code into the application's web interface. The vulnerability arises from insufficient input sanitization of URI parameters, allowing arbitrary script execution in the context of the victim's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Netegrity IdentityMinder (version not specified)
No auth needed
Prerequisites: Victim must click a malicious link
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappscgi
https://www.exploit-db.com/exploits/24245

The provided text describes a cross-site scripting (XSS) vulnerability in Netegrity IdentityMinder, where user-supplied URI input is not properly sanitized. An example exploit URI is included to demonstrate the vulnerability.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Netegrity IdentityMinder
No auth needed
Prerequisites: A victim must click on a malicious link
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10645
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108881203114336&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16618

Scores

EPSS 0.0201
EPSS Percentile 79.0%

Details

Status published
Products (4)
netegrity/identityminder web_5.6
netegrity/identityminder web_5.6_sp1
netegrity/identityminder web_5.6_sp2
netegrity/policy_server 5.5
Published Aug 06, 2004
Tracked Since Feb 18, 2026