Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2705. PoCs published by Arshan Dabirsiaghi.
AI-analyzed exploit summary The provided text describes a security-bypass vulnerability in Computer Associates SiteMinder due to improper input validation, allowing attackers to bypass XSS protections. The example URL demonstrates a potential exploit vector using a specific encoding technique.
Description
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.
Exploits (1)
The provided text describes a security-bypass vulnerability in Computer Associates SiteMinder due to improper input validation, allowing attackers to bypass XSS protections. The example URL demonstrates a potential exploit vector using a specific encoding technique.