-----BEGIN PGP SIGNED MESSAGE----- //@(#) Mordred Security Labs advisory Release date: March 14, 2003 Name: RSA ClearTrust Cross Site Scripting issues Risk: low Author: Sir Mordred (mordred@s-mail.com, http://mslabs.iwebland.com) I. Description: The RSA ClearTrust is a Web access management solution that helps enable secure access to Web-based resources. RSA ClearTrust software is designed to work within intranets, extranets, portals and exchange infrastructures — all while providing users with transparent, single sign-on (SSO) across multiple applications. For more info please visit http://www.rsasecurity.com II. Details: RSA ClearTrust login page suffers from a Cross Site Scripting vulnerabilities: https://victim.com/cleartrust/ct_logon.asp?CTLoginErrorMsg=