Juniper Networks Secure Access 2000 'rdremediate.cgi' Cross Site Scripting Vulnerability
BID:28034
Info
Juniper Networks Secure Access 2000 'rdremediate.cgi' Cross Site Scripting Vulnerability
| Bugtraq ID: | 28034 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1180 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2008 12:00AM |
| Updated: | Apr 16 2015 06:05PM |
| Credit: | Richard Brain of ProCheckUp Ltd. is credited with discovering this vulnerability. |
| Vulnerable: |
Juniper Networks Secure Access 2000 5.5R1 Build 11711 Juniper Networks Secure Access 2000 0 |
| Not Vulnerable: |
Juniper Networks Secure Access 2000 5.5R3 |
Discussion
Juniper Networks Secure Access 2000 'rdremediate.cgi' Cross Site Scripting Vulnerability
Juniper Networks Secure Access 2000 is prone to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Juniper Networks Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.
Juniper Networks Secure Access 2000 is prone to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Juniper Networks Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.
Exploit / POC
Juniper Networks Secure Access 2000 'rdremediate.cgi' Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI and HTTP request are available:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI and HTTP request are available:
Solution / Fix
Juniper Networks Secure Access 2000 'rdremediate.cgi' Cross Site Scripting Vulnerability
Solution:
The vendor released Secure Access 2000 5.5R3 to address this issue. Please see the references for more information.
Solution:
The vendor released Secure Access 2000 5.5R3 to address this issue. Please see the references for more information.
References
Juniper Networks Secure Access 2000 'rdremediate.cgi' Cross Site Scripting Vulnerability
References:
References:
- Juniper Networks Homepage (Juniper Networks)
- Secure Access 2000 Homepage (Juniper Networks)
- PR07-41: XSS on Juniper Networks Secure Access 2000 (ProCheckUp Research
) - PR07-41: XSS on Juniper Networks Secure Access 2000 (ProCheckUp)