[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft Forefront Unified Access Gateway multiple XSS vulnerabilities - MS10-089

ID: oval:org.secpod.oval:def:1369Date: (C)2011-06-29   (M)2022-04-14
Class: PATCHFamily: windows




The host is missing a critical security update according to Microsoft security bulletin, MS10-089. The update is required to fix multiple cross-site scripting vulnerabilities. Multiple flaws are present in the Sginurl.asp in Microsoft Forefront Unified Access Gateway. Successful exploitation could allow an attacker to gain the cookie-based authentication credentials and issue commands to the UAG server in the context of the victim.

Platform:
Microsoft Windows Server 2008
Product:
Forefront Unified Access Gateway 2010
Reference:
MS10-089
CVE-2010-2732
CVE-2010-2733
CVE-2010-2734
CVE-2010-3936
CVE    4
CVE-2010-2734
CVE-2010-2733
CVE-2010-2732
CVE-2010-3936
...
CPE    4
cpe:/a:microsoft:forefront_unified_access_gateway:2010:update1
cpe:/a:microsoft:forefront_unified_access_gateway:2010:update2
cpe:/a:microsoft:forefront_unified_access_gateway:2010:-
cpe:/o:microsoft:windows_server_2008::r2:x64
...
XCCDF    1
xccdf_com.secpod_benchmark_microsoft-windows-server-2008

© SecPod Technologies