CVE-2007-5923
CA eTrust SiteMinder Agent - Cross-Site Scripting via SMAUTHREASON Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5923. PoCs published by Giuseppe Gottardi.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Computer Associates SiteMinder Web Agent by injecting malicious JavaScript into the SMAUTHREASON parameter. The PoC shows how arbitrary script code can be executed in the context of an affected site.
Description
Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attackers to inject arbitrary web script or HTML via the SMAUTHREASON parameter, a different vector than CVE-2005-2204.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Computer Associates SiteMinder Web Agent by injecting malicious JavaScript into the SMAUTHREASON parameter. The PoC shows how arbitrary script code can be executed in the context of an affected site.