Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RSA ACE代理和认证代理图形跨站脚本漏洞
Vulnerability Description
RSA认证代理软件是非常流行的动态认证工具,可控制对公司网络、基于Web的应用和操作系统的访问。 由于缺少输入验证,RSA认证代理中存在跨站脚本漏洞。攻击者可以通过向"image"参数中注入客户端脚本,导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A