Great, you use CA SiteMinder, but you broke it!
netspi.com | blog | #sql-injection | #xss | #sso | #misconfiguration | #ca-siteminder | #web-access-management
Summary
CA SiteMinder blocks SQL injection and XSS out of the box, but tweaking it to pass full SQL statements from browsers reintroduces those flaws, and its own standard pages can become XSS vectors.
- Published
- Collected
Skip to content