Posted: Sat Jul 30, 2005 2:46 pm Post subject: Flaw in ISA Server Error Pages
ISA Server contains a number of HTML-based error pages that allow the server to respond to a client requesting a Web resource with a customized error. A cross-site scripting vulnerability exists in many of these error pages that are returned by ISA Server under specific error conditions.