SolarWinds Serv-U FTP Server CVE-2018-19934 Cross Site Scripting Vulnerability
BID:107554
Info
SolarWinds Serv-U FTP Server CVE-2018-19934 Cross Site Scripting Vulnerability
| Bugtraq ID: | 107554 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-19934 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2019 12:00AM |
| Updated: | Jan 31 2019 12:00AM |
| Credit: | Chris |
| Vulnerable: |
SolarWinds Serv-U 15.1.6.25 |
| Not Vulnerable: |
SolarWinds Serv-U 15.1.6 hotfix 3 |
Discussion
SolarWinds Serv-U FTP Server CVE-2018-19934 Cross Site Scripting Vulnerability
SolarWinds Serv-U FTP Server is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
SolarWinds Serv-U FTP Server 15.1.6.25 is vulnerable; other versions may also be affected.
SolarWinds Serv-U FTP Server is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
SolarWinds Serv-U FTP Server 15.1.6.25 is vulnerable; other versions may also be affected.
Exploit / POC
SolarWinds Serv-U FTP Server CVE-2018-19934 Cross Site Scripting Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
SolarWinds Serv-U FTP Server CVE-2018-19934 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SolarWinds Serv-U FTP Server CVE-2018-19934 Cross Site Scripting Vulnerability
References:
References:
- Reflected XSS in n SolarWinds Serv-U FTP Server (Seclists.org)
- Serv-U 15.1.6 Hotfix 3 Release Notes (SolarWinds)
- SolarWinds Home Page (SolarWinds)