Xerox WorkCentre Products HTML Injection Vulnerability
BID:16727
Info
Xerox WorkCentre Products HTML Injection Vulnerability
| Bugtraq ID: | 16727 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2006 12:00AM |
| Updated: | Feb 22 2006 04:22PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Xerox WorkCentre Pro 275 Xerox WorkCentre Pro 265 Xerox WorkCentre Pro 255 Xerox WorkCentre Pro 245 Xerox WorkCentre Pro 238 Xerox WorkCentre Pro 232 Xerox WorkCentre 275 Xerox WorkCentre 265 Xerox WorkCentre 255 Xerox WorkCentre 245 Xerox WorkCentre 238 Xerox WorkCentre 232 |
| Not Vulnerable: | |
Discussion
Xerox WorkCentre Products HTML Injection Vulnerability
Xerox WorkCentre Products are prone to an HTML-injection vulnerability. The application on these devices fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue is reported to affect these versions:
- WorkCentre 232, 238, 245, 255, 265, and 275
- WorkCentre Pro 232, 238, 245, 255, 265, and 275
Other versions may also be vulnerable.
Xerox WorkCentre Products are prone to an HTML-injection vulnerability. The application on these devices fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue is reported to affect these versions:
- WorkCentre 232, 238, 245, 255, 265, and 275
- WorkCentre Pro 232, 238, 245, 255, 265, and 275
Other versions may also be vulnerable.
Exploit / POC
Xerox WorkCentre Products HTML Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Xerox WorkCentre Products HTML Injection Vulnerability
Solution:
The vendor has released System Software Version 14.027.24.015 and 13.027.24.015 to address this issue. Please contact a Xerox customer support representative for assistance.
Solution:
The vendor has released System Software Version 14.027.24.015 and 13.027.24.015 to address this issue. Please contact a Xerox customer support representative for assistance.
References
Xerox WorkCentre Products HTML Injection Vulnerability
References:
References:
- Xerox Homepage (Xerox)
- XEROX Security Bulletin XRX006-01 (Xerox)