Short Name |
HTTP:IIS:MS-RD-WEB-ACCESS-XSS |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft Remote Desktop Web Access Cross Site Scripting |
Release Date |
2011/08/08 |
Update Number |
1969 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a know flaw in Microsoft Remote Desktop Web Access. An XSS vulnerability exists in Microsoft's Remote Desktop Web Access where Javascript can be injected back to the user in the resulting page, effectively allowing attacker-controlled JavaScript to run in the context of the user clicking the link.
Microsoft Remote Desktop Web Access is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.