Apache Geronimo Multiple Input Validation Vulnerabilities
BID:16260
Info
Apache Geronimo Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 16260 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0254 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2006 12:00AM |
| Updated: | Aug 25 2008 10:45PM |
| Credit: | Oliver Karow is credited with the discovery of this vulnerability. |
| Vulnerable: |
Redhat Red Hat Network Satellite Server 5.0 Redhat Red Hat Network Satellite Server 4.2 Redhat Network Satellite (for RHEL 4) 5.1 Redhat Network Satellite (for RHEL 4) 4.2 Redhat Network Satellite (for RHEL 3) 4.2 Apache Geronimo 1.0 |
| Not Vulnerable: |
Apache Geronimo 1.1 Apache Geronimo 1.0.1 |
Discussion
Apache Geronimo Multiple Input Validation Vulnerabilities
Apache Geronimo is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input.
A successful exploit could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. The attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Apache Geronimo is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input.
A successful exploit could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. The attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
Apache Geronimo Multiple Input Validation Vulnerabilities
An exploit is not required.
Example URIs have been provided:
http://www.example.com/jsp-examples/cal/cal2.jsp?time="/><script>alert('Gotcha')</script>
http://www.example.com/script-that-dont-has-to-exist.jsp?foobar="/><script>alert(document.cookie)</script>
An exploit is not required.
Example URIs have been provided:
http://www.example.com/jsp-examples/cal/cal2.jsp?time="/><script>alert('Gotcha')</script>
http://www.example.com/script-that-dont-has-to-exist.jsp?foobar="/><script>alert(document.cookie)</script>
Solution / Fix
Apache Geronimo Multiple Input Validation Vulnerabilities
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
References
Apache Geronimo Multiple Input Validation Vulnerabilities
References:
References:
- Apache Geronimo 1.0 - CSS and persistent HTML-Injection vulnerabilities (Oliver Karow)
- Apache Geronimo Web Site (Apache)
- RHSA-2008:0261-4 Moderate: Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0524-4 Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0627-2 Low: Red Hat Network Proxy Server security update (Red Hat)