Hostflow New_Ticket.CGI Cross-Site Scripting Vulnerability
BID:18695
CVE-2006-3328 |Info
Hostflow New_Ticket.CGI Cross-Site Scripting Vulnerability
| Bugtraq ID: | 18695 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2006 12:00AM |
| Updated: | Jun 28 2006 07:40PM |
| Credit: | r0t is credited with the discovery of this vulnerability. |
| Vulnerable: |
StarFlow Software HostFlow 2.2.15 |
| Not Vulnerable: | |
Discussion
Hostflow New_Ticket.CGI Cross-Site Scripting Vulnerability
Hostflow is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 2.2.15; prior versions may also be vulnerable.
Hostflow is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 2.2.15; prior versions may also be vulnerable.
Exploit / POC
Hostflow New_Ticket.CGI Cross-Site Scripting Vulnerability
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
Hostflow New_Ticket.CGI Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Hostflow New_Ticket.CGI Cross-Site Scripting Vulnerability
References:
References:
- HostFlow Home Page (StarFlow Software )
- Unsecured System-Hostflow vuln. (r0t)