CVE-2008-2027
Last modified
CVE-2008-2027 is a vulnerability of currently unknown severity. Open redirect vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258 for Web for IIS, when accessed via certain browsers such as Mozilla Firefox, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an ftp URL in the url parameter to a Redirect action.. EPSS estimates a 1.12% chance of exploitation in the next 30 days.
Description
Open redirect vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258 for Web for IIS, when accessed via certain browsers such as Mozilla Firefox, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an ftp URL in the url parameter to a Redirect action.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Authentication Agent | 5.3.0.258 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2027?
How severe is CVE-2008-2027?
How do I fix CVE-2008-2027?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2021Heap-based buffer overflow in Lhaplus before 1.57 allows rem…
- CVE-2008-2022Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 …
- CVE-2008-2023Multiple SQL injection vulnerabilities in PD9 Software MegaB…
- CVE-2008-2024Cross-site scripting (XSS) vulnerability in index.php in min…
- CVE-2008-2025Cross-site scripting (XSS) vulnerability in Apache Struts be…
- CVE-2008-2026Cross-site scripting (XSS) vulnerability in WebID/IISWebAgen…
- CVE-2008-2028miniBB 2.2, and possibly earlier, when register_globals is e…
- CVE-2008-2029Multiple SQL injection vulnerabilities in (1) setup_mysql.ph…
- CVE-2008-2030Cross-site scripting (XSS) vulnerability in installControl.p…
- CVE-2008-2031VicFTPS 5.0 allows remote attackers to cause a denial of ser…
- CVE-2008-2032The FTP service in Acritum Femitter Server 1.03 allows remot…
- CVE-2008-2033Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2008-2027?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
