Description
|
|
Two vulnerabilities have been identified in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition), which could be exploited to cause a denial of service or execute arbitrary scripting code.
The first issue is caused by an error in the firewall engine when handling the session state for Web proxy or Web publishing listeners, which could allow a remote user to cause a Web listener to stop responding to new requests.
The second vulnerability is caused by an input validation error in the HTML forms authentication component (cookieauth.dll), which could be exploited to conduct cross site scripting attacks.
|