Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Great, you use CA SiteMinder, but you broke it!

Summary

CA SiteMinder blocks SQL injection and XSS out of the box, but tweaking it to pass full SQL statements from browsers reintroduces those flaws, and its own standard pages can become XSS vectors.
Published
Collected

original ↗