NetworkActiv Web Server Cross-Site Scripting Vulnerability
BID:14473
Info
NetworkActiv Web Server Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14473 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2005 12:00AM |
| Updated: | Aug 04 2005 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Secunia Research. |
| Vulnerable: |
NetworkActiv NetworkActiv Web Server 3.5.13 NetworkActiv NetworkActiv Web Server 3.0.1 .1 NetworkActiv NetworkActiv Web Server 2.0 .0.6 NetworkActiv NetworkActiv Web Server 1.0 |
| Not Vulnerable: |
NetworkActiv NetworkActiv Web Server 3.5.14 |
Discussion
NetworkActiv Web Server Cross-Site Scripting Vulnerability
NetworkActiv Web Server is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
NetworkActiv Web Server is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
NetworkActiv Web Server Cross-Site Scripting Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com?">[code]
No exploit is required.
The following proof of concept URI is available:
http://www.example.com?">[code]
Solution / Fix
NetworkActiv Web Server Cross-Site Scripting Vulnerability
Solution:
The vendor has addressed this issue in NetworkActiv Web Server version 3.5.14:
NetworkActiv NetworkActiv Web Server 1.0
NetworkActiv NetworkActiv Web Server 2.0 .0.6
NetworkActiv NetworkActiv Web Server 3.0.1 .1
NetworkActiv NetworkActiv Web Server 3.5.13
Solution:
The vendor has addressed this issue in NetworkActiv Web Server version 3.5.14:
NetworkActiv NetworkActiv Web Server 1.0
-
NetworkActiv NetworkActivWebServerV3.5.exe
http://www.networkactiv.com/NetworkActivWebServerV3.5.exe
NetworkActiv NetworkActiv Web Server 2.0 .0.6
-
NetworkActiv NetworkActivWebServerV3.5.exe
http://www.networkactiv.com/NetworkActivWebServerV3.5.exe
NetworkActiv NetworkActiv Web Server 3.0.1 .1
-
NetworkActiv NetworkActivWebServerV3.5.exe
http://www.networkactiv.com/NetworkActivWebServerV3.5.exe
NetworkActiv NetworkActiv Web Server 3.5.13
-
NetworkActiv NetworkActivWebServerV3.5.exe
http://www.networkactiv.com/NetworkActivWebServerV3.5.exe
References
NetworkActiv Web Server Cross-Site Scripting Vulnerability
References:
References:
- NetworkActiv Web Server Cross-Site Scripting Vulnerability (Secunia)
- NetworkActiv Web Server Product Page (NetworkActiv)