MS.Forefront.UAG.Server.default.asp.XSS

description-logoDescription

This indicates an attack attempt against a Cross Site Scripting (XSS) vulnerability in Microsoft UAG Server.
The vulnerability is caused by an error when the vulnerable software handles a malicious HTTP POST request.

affected-products-logoAffected Products

Microsoft Forefront Unified Access Gateway 2010
Microsoft Forefront Unified Access Gateway 2010 Update 1
Microsoft Forefront Unified Access Gateway 2010 Update 2
Microsoft Forefront Unified Access Gateway 2010 Service Pack 1

Impact logoImpact

Information Disclosure: Cross Site Scripting.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for the suggested workaround:
http://www.microsoft.com/technet/security/Bulletin/ms11-079.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)