Xerver Multiple Input Validation Vulnerabilities
BID:15135
Info
Xerver Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15135 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2005 12:00AM |
| Updated: | Oct 19 2005 12:00AM |
| Credit: | Ziv Kamir of Global Security Solution IT is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Xerver Xerver 4.17 |
| Not Vulnerable: |
Xerver Xerver 4.20 |
Discussion
Xerver Multiple Input Validation Vulnerabilities
Xerver is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit a vulnerability to disclose the contents of any Web accessible script. Information obtained may aid in further attacks.
An attacker can retrieve a directory listing of any Web accessible folders. Information obtained may aid in further attacks.
An attacker can perform cross-site scripting attacks. This may be leveraged to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Xerver is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit a vulnerability to disclose the contents of any Web accessible script. Information obtained may aid in further attacks.
An attacker can retrieve a directory listing of any Web accessible folders. Information obtained may aid in further attacks.
An attacker can perform cross-site scripting attacks. This may be leveraged to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Xerver Multiple Input Validation Vulnerabilities
No exploit is required.
The following proof of concepts are available:
http://www.example.com/Test.pl. ( '.' )
http://www.example.com/Test.php%2e ( '%2e' )
http://www.example.com/%00/
http://www.example.com/%00/<script>alert('X.S.S')</script>
No exploit is required.
The following proof of concepts are available:
http://www.example.com/Test.pl. ( '.' )
http://www.example.com/Test.php%2e ( '%2e' )
http://www.example.com/%00/
http://www.example.com/%00/<script>alert('X.S.S')</script>
Solution / Fix
Xerver Multiple Input Validation Vulnerabilities
Solution:
The vendor has addressed these issues in Xerver version 4.20:
Xerver Xerver 4.17
Solution:
The vendor has addressed these issues in Xerver version 4.20:
Xerver Xerver 4.17
-
Xerver Xerver 4.20
http://www.javascript.nu/xerver/