RaidenHTTPD Prior to 2.0.22 Unspecified Cross Site Scripting Vulnerability
BID:27628
Info
RaidenHTTPD Prior to 2.0.22 Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 27628 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0622 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | An unknown researcher disclosed this issue via the JVN. |
| Vulnerable: |
RaidenHTTPD RaidenHTTPD 2.0.19 RaidenHTTPD RaidenHTTPD 2.0.14 RaidenHTTPD RaidenHTTPD 2.0.13 RaidenHTTPD RaidenHTTPD 1.1.49 RaidenHTTPD RaidenHTTPD 1.1.48 RaidenHTTPD RaidenHTTPD 1.1.47 RaidenHTTPD RaidenHTTPD 1.1.34 RaidenHTTPD RaidenHTTPD 1.1.32 RaidenHTTPD RaidenHTTPD 1.1.27 |
| Not Vulnerable: |
RaidenHTTPD RaidenHTTPD 2.0.22 |
Discussion
RaidenHTTPD Prior to 2.0.22 Unspecified Cross Site Scripting Vulnerability
RaidenHTTPD is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help an attacker steal cookie-based authentication credentials and launch other attacks.
RaidenHTTPD 2.0.19 is vulnerable to this issue; prior versions may also be affected.
RaidenHTTPD is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help an attacker steal cookie-based authentication credentials and launch other attacks.
RaidenHTTPD 2.0.19 is vulnerable to this issue; prior versions may also be affected.
Exploit / POC
RaidenHTTPD Prior to 2.0.22 Unspecified Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
RaidenHTTPD Prior to 2.0.22 Unspecified Cross Site Scripting Vulnerability
Solution:
The vendor has released RaidenHTTPD 2.0.22, which addresses this vulnerability. Please see the references for more information.
RaidenHTTPD RaidenHTTPD 2.0.19
Solution:
The vendor has released RaidenHTTPD 2.0.22, which addresses this vulnerability. Please see the references for more information.
RaidenHTTPD RaidenHTTPD 2.0.19
-
RaidenHTTPD RaidenHTTPD_PHP5.exe
http://www.raidenmaild.com/download/RaidenHTTPD_PHP5.exe
References
RaidenHTTPD Prior to 2.0.22 Unspecified Cross Site Scripting Vulnerability
References:
References:
- RaidenHTTPD Homepage (RaidenHTTPD)
- RaidenHTTPD Security (RaidenHTTPD)
- JVN#91868305 (JVN)