2 results (0.005 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

04 May 2011 — Multiple cross-site scripting (XSS) vulnerabilities in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) anteriores a v6.2.5, permite a atacantes remotos inyectar secuencias de comandos web o HTML a tra... • http://osvdb.org/72124 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

04 May 2011 — Open redirect vulnerability in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en Administrative Console en CA Arcot WebFort Versatile Authentication Server (VAS)anterioes a v6.2.5, permite a atacantes remotos redireccionar a usuarios a sitios web de su elección y llevar a cabo ataques de phishing a trav... • http://osvdb.org/72125 • CWE-20: Improper Input Validation •