|
Microsoft Forefront Unified Access Gateway contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because unspecified input passed to the UAG Mobile Portal website is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.It can allow an attacker to issue commands to the UAG server in the context of the targeted user.
|