CVE-2008-1470
RSA WebID - Cross-Site Scripting via IISWebAgentIF.dll postdata Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-1470. PoCs published by s4squatch, quentin.berdugo.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in IISWebAgentIF.dll by injecting a script tag into the 'postdata' parameter. The vulnerability allows arbitrary JavaScript execution in the context of the victim's browser session.
Description
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.
Exploits (2)
This exploit demonstrates a reflected XSS vulnerability in IISWebAgentIF.dll by injecting a script tag into the 'postdata' parameter. The vulnerability allows arbitrary JavaScript execution in the context of the victim's browser session.
This exploit demonstrates a reflected XSS vulnerability in RSA WebID by injecting a malicious script into the 'postdata' parameter. The script executes in the context of the affected site, potentially stealing cookie-based authentication credentials.