Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26424 | vdb entry |
https://knowledge.rsasecurity.com/dlcpages/rsa_securid/securid_dlc_aaweb.asp | |
http://www.osvdb.org/20151 | vdb entry exploit |
http://www.metasploit.com/projects/Framework/exploits.html#rsa_iiswebagent_redirect | exploit |
http://secunia.com/advisories/17281 | vendor advisory third party advisory exploit |