Infoblox DNS One Script Injection Vulnerability
BID:10573
Info
Infoblox DNS One Script Injection Vulnerability
| Bugtraq ID: | 10573 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0606 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery is credited to c3rb3r <[email protected]>. |
| Vulnerable: |
Infoblox DNS One Appliance 2.4 .0-8A Infoblox DNS One Appliance 2.4 .0-8 |
| Not Vulnerable: | |
Discussion
Infoblox DNS One Script Injection Vulnerability
The Infoblox DNS One appliance has been reported prone to a script injection vulnerability. A remote attacker could potentially gain access to the vulnerable device or potentially execute script on the computer used to access the device. The issue is only present if the device is being used for DHCP.
The Infoblox DNS One appliance has been reported prone to a script injection vulnerability. A remote attacker could potentially gain access to the vulnerable device or potentially execute script on the computer used to access the device. The issue is only present if the device is being used for DHCP.
Exploit / POC
Infoblox DNS One Script Injection Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Infoblox DNS One Script Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
It has been reported that this issue has been addressed in versions 2.4.0-9 and 2.4.0-9A of the device firmware. This has not been confirmed by Symantec.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
It has been reported that this issue has been addressed in versions 2.4.0-9 and 2.4.0-9A of the device firmware. This has not been confirmed by Symantec.
References
Infoblox DNS One Script Injection Vulnerability
References:
References:
- DNS One Network Identity Appliance (Infoblox)
- Script injection in DNSONE appliance (c3rb3r
)