Hal Networks Multiple Products Cross-Site Scripting Vulnerabilities
BID:27513
Info
Hal Networks Multiple Products Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 27513 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0522 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Syuuya Ueki is credited with the discovery of these issues. |
| Vulnerable: |
Hal Networks Shopping Cart System 0 Hal Networks Shop_hal_v1 0 Hal Networks PHP cart 0 Hal Networks Perl / CGI cart 0 |
| Not Vulnerable: | |
Discussion
Hal Networks Multiple Products Cross-Site Scripting Vulnerabilities
Multiple Hal Networks products are prone to cross-site scripting vulnerabilities because the applications fail to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
For information on which products are vulnerable, please see the referenced advisories and contact the vendor.
Multiple Hal Networks products are prone to cross-site scripting vulnerabilities because the applications fail to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
For information on which products are vulnerable, please see the referenced advisories and contact the vendor.
Exploit / POC
Hal Networks Multiple Products Cross-Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Hal Networks Multiple Products Cross-Site Scripting Vulnerabilities
Solution:
Reportedly, the vendor has released updates to address these issues, but Symantec has not verified this. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has released updates to address these issues, but Symantec has not verified this. Please contact the vendor for more information.
References
Hal Networks Multiple Products Cross-Site Scripting Vulnerabilities
References:
References:
- Hal Networks Homepage (Hal Networks)
- JVN#01162446 (JVN)
- JVNDB-2008-000006 (JVNDB)