CVE-2018-1233
RSA Authentication Agent for Web XSS / Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.
RSA Authentication Agent en versiones 8.0.1 y anteriores para Web para IIS y Apache Web Server se ve afectado por una vulnerabilidad Cross-Site Scripting (XSS). Los atacantes podrían explotar esta vulnerabilidad para ejecutar HTML o código JavaScript arbitrarios en la sesión del buscador del usuario, en el contexto de la página web afectada.
RSA Authentication Agent for Web for both IIS and Apache Web Server version 8.0. 1 and earlier contain multiple vulnerabilities that could potentially be exploit ed by malicious users to compromise affected systems. These issues include cross site scripting, buffer overflow, and information disclosure.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-03-28 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Mar/60 | Mailing List |
|
http://www.securitytracker.com/id/1040577 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rsa Search vendor "Rsa" | Authentication Agent For Web Search vendor "Rsa" for product "Authentication Agent For Web" | <= 8.0.1 Search vendor "Rsa" for product "Authentication Agent For Web" and version " <= 8.0.1" | apache_web_server |
Affected
| ||||||
Rsa Search vendor "Rsa" | Authentication Agent For Web Search vendor "Rsa" for product "Authentication Agent For Web" | <= 8.0.1 Search vendor "Rsa" for product "Authentication Agent For Web" and version " <= 8.0.1" | iis |
Affected
|