Ingate Administrative Interface Cross-Site Scripting Vulnerability
BID:14812
Info
Ingate Administrative Interface Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14812 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2005 12:00AM |
| Updated: | Jun 07 2006 09:12PM |
| Credit: | Jonas Stare is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ingate SIParator 4.2.3 Ingate SIParator 4.2.2 Ingate SIParator 4.2.1 Ingate SIParator 4.4 Ingate Firewalll 4.4 Ingate Firewall 4.2 .3 Ingate Firewall 4.2 .2 Ingate Firewall 4.2 .1 |
| Not Vulnerable: |
Ingate SIParator 4.4.1 Ingate Firewall 4.4.1 |
Discussion
Ingate Administrative Interface Cross-Site Scripting Vulnerability
Ingate Firewall and SIParator are prone to a cross-site scripting vulnerability. This is due to a failure to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting administrative user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Ingate Firewall and SIParator are prone to a cross-site scripting vulnerability. This is due to a failure to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting administrative user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Ingate Administrative Interface Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Ingate Administrative Interface Cross-Site Scripting Vulnerability
Solution:
The vendor has released fixes to address this issue. Please contact the vendor for more information on obtaining and applying fixes.
Solution:
The vendor has released fixes to address this issue. Please contact the vendor for more information on obtaining and applying fixes.
References
Ingate Administrative Interface Cross-Site Scripting Vulnerability
References:
References: