GS07-02 RSA Keon Multiple Cross-Site Scripting Vulnerabilities

Tuesday, 30 October 2007

Date & Version : 07/31/2007 - 1.1
Description :

RSA KEON Registration Authority Web Interface has multiple Cross-Site Scripting Vulnerabilities. Request-spk.xuda and Add-msie-request.xuda components of RSA KEON are vulnerable to Cross-Site Scripting attacks. An attacker could use these vulnerabilities for manipulating the registration information, phishing and other client side attacks.

Risk Level : Medium

Impact : Gain Access

Systems Affected :

RSA KEON Registration Authority Software

Remedy :

Contact RSA and visit for remediation.

Credits :

Fatih Ozavci (GamaTEAM Member)
Caglar Cakici (GamaTEAM Member)
It's detected using GamaSEC Exploit Framework Security Solutions (

Original Advisory Link :

References: CERT - Vulnerability Note VU#342793

Share this content:
Home | News | Articles | Advisories | Submit | Alerts | Links | What is XSS | About | Contact | Some Rights Reserved.