Lucene search

K
cveMitreCVE-2004-0672
HistoryAug 06, 2004 - 4:00 a.m.

CVE-2004-0672

2004-08-0604:00:00
mitre
web.nvd.nist.gov
24
cve-2004-0672
cross-site scripting
xss
netegrity identityminder
web edition
security vulnerabilities
remote code execution

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

High

EPSS

0.007

Percentile

80.4%

Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.

Affected configurations

Nvd
Node
netegrityidentityminderMatchweb_5.6
OR
netegrityidentityminderMatchweb_5.6_sp1
OR
netegrityidentityminderMatchweb_5.6_sp2
OR
netegritypolicy_serverMatch5.5
VendorProductVersionCPE
netegrityidentityminderweb_5.6cpe:2.3:a:netegrity:identityminder:web_5.6:*:*:*:*:*:*:*
netegrityidentityminderweb_5.6_sp1cpe:2.3:a:netegrity:identityminder:web_5.6_sp1:*:*:*:*:*:*:*
netegrityidentityminderweb_5.6_sp2cpe:2.3:a:netegrity:identityminder:web_5.6_sp2:*:*:*:*:*:*:*
netegritypolicy_server5.5cpe:2.3:a:netegrity:policy_server:5.5:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

High

EPSS

0.007

Percentile

80.4%

Related for CVE-2004-0672