Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-3300
Description:Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.
Test IDs: 1.3.6.1.4.1.25623.1.0.66514   1.3.6.1.4.1.25623.1.0.801148  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-3300
Debian Security Information: DSA-1947 (Google Search)
http://www.debian.org/security/2009/dsa-1947
http://secunia.com/advisories/37237
http://www.vupen.com/english/advisories/2009/3150
XForce ISS Database: identity-url-xss(54140)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54140




© 1998-2025 E-Soft Inc. All rights reserved.