RaidenHTTPD Unspecified Cross Site Scripting Vulnerability
BID:24568
Info
RaidenHTTPD Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 24568 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3343 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Fukumori via JVN is credited with the discovery of this vulnerability. |
| Vulnerable: |
RaidenHTTPD RaidenHTTPD 2.0.13 |
| Not Vulnerable: |
RaidenHTTPD RaidenHTTPD 2.0.14 |
Discussion
RaidenHTTPD Unspecified Cross Site Scripting Vulnerability
RaidenHTTPD is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
RaidenHTTPD 2.0.13 is vulnerable to this issue; prior versions may also be affected.
RaidenHTTPD is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
RaidenHTTPD 2.0.13 is vulnerable to this issue; prior versions may also be affected.
Exploit / POC
RaidenHTTPD Unspecified Cross Site Scripting Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
RaidenHTTPD Unspecified Cross Site Scripting Vulnerability
Solution:
The vendor has released an updated version that addresses this vulnerability. Please see the references for more information.
Solution:
The vendor has released an updated version that addresses this vulnerability. Please see the references for more information.
References
RaidenHTTPD Unspecified Cross Site Scripting Vulnerability
References:
References:
- JVN#90438169 (JVN)
- RaidenHTTPD Homepage (RaidenHTTPD)
- RaidenHTTPD Security (RaidenHTTPD)