Info2html Unspecified Cross-Site/Cross-Frame Scripting Vulnerabilities
BID:13885
Info
Info2html Unspecified Cross-Site/Cross-Frame Scripting Vulnerabilities
| Bugtraq ID: | 13885 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2005 12:00AM |
| Updated: | Jun 07 2005 12:00AM |
| Credit: | These issues were announced by SUSE. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SuSE Linux 7.3 sparc SuSE Linux 7.3 ppc SuSE Linux 7.3 i386 SuSE Linux 7.3 SuSE Linux 7.2 i386 SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.1 SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 i386 SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 i386 SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 ppc SuSE Linux 6.3 alpha SuSE Linux 6.3 SuSE Linux 6.2 SuSE Linux 6.1 alpha SuSE Linux 6.1 SuSE Linux 6.0 SuSE Linux 5.3 SuSE Linux 5.2 SuSE Linux 5.1 SuSE Linux 5.0 SuSE Linux 4.4.1 SuSE Linux 4.4 SuSE Linux 4.3 SuSE Linux 4.2 SuSE Linux 4.0 SuSE Linux 3.0 SuSE Linux 2.0 SuSE Linux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SuSE eMail Server III S.u.S.E. SuSE eMail Server 3.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Office Server S.u.S.E. Linux IMAP Server 1.0 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server info2html info2html 1.4 info2html info2html 1.3 info2html info2html 1.2 info2html info2html 1.1 info2html info2html 1.0 d |
| Not Vulnerable: | |
Discussion
Info2html Unspecified Cross-Site/Cross-Frame Scripting Vulnerabilities
info2html is prone to multiple unspecified cross-site/cross-frame scripting vulnerabilities.
The exact cause of these issues is currently unknown, however, it is conjectured that an attacker may execute arbitrary HTML or script code in a user's browser due to a lack of argument escaping. This may allow the attacker to steal cookie-based authentication credentials or carry out other attacks.
All versions of info2html are considered vulnerable at the moment.
This BID will be updated when more information is available.
info2html is prone to multiple unspecified cross-site/cross-frame scripting vulnerabilities.
The exact cause of these issues is currently unknown, however, it is conjectured that an attacker may execute arbitrary HTML or script code in a user's browser due to a lack of argument escaping. This may allow the attacker to steal cookie-based authentication credentials or carry out other attacks.
All versions of info2html are considered vulnerable at the moment.
This BID will be updated when more information is available.
Exploit / POC
Info2html Unspecified Cross-Site/Cross-Frame Scripting Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Info2html Unspecified Cross-Site/Cross-Frame Scripting Vulnerabilities
Solution:
SUSE Linux has released advisory SUSE-SR:2005:014 to address these and other issues. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
SUSE Linux has released advisory SUSE-SR:2005:014 to address these and other issues. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Info2html Unspecified Cross-Site/Cross-Frame Scripting Vulnerabilities
References:
References:
- info2html Home Page (info2html)