National Rail Enquiries Live Departure Boards Gadget Remote Script Code Execution Vulnerability
BID:28933
Info
National Rail Enquiries Live Departure Boards Gadget Remote Script Code Execution Vulnerability
| Bugtraq ID: | 28933 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2011 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | R Dominguez Vega of MWR InfoSecurity |
| Vulnerable: |
National Rail Enquiries Live Departure Boards Gadget 1.0 |
| Not Vulnerable: |
National Rail Enquiries Live Departure Boards Gadget 1.1 |
Discussion
National Rail Enquiries Live Departure Boards Gadget Remote Script Code Execution Vulnerability
National Rail Enquiries Live Departure Board Gadget is prone to a vulnerability that lets remote attackers execute arbitrary script code because the application fails to properly sanitize user-supplied input.
To exploit this issue, attackers must be able to perform a man-in-the-middle attack against the website that the gadget accesses for departure information.
An attacker may leverage this issue to execute arbitrary code on an affected computer with the privileges of the affected process. This may facilitate unauthorized access.
Versions prior to National Rail Enquiries Live Departure Board Gadget 1.1 are vulnerable.
National Rail Enquiries Live Departure Board Gadget is prone to a vulnerability that lets remote attackers execute arbitrary script code because the application fails to properly sanitize user-supplied input.
To exploit this issue, attackers must be able to perform a man-in-the-middle attack against the website that the gadget accesses for departure information.
An attacker may leverage this issue to execute arbitrary code on an affected computer with the privileges of the affected process. This may facilitate unauthorized access.
Versions prior to National Rail Enquiries Live Departure Board Gadget 1.1 are vulnerable.
Exploit / POC
National Rail Enquiries Live Departure Boards Gadget Remote Script Code Execution Vulnerability
Attackers exploit this issue by performing man-in-the-middle attacks.
Attackers exploit this issue by performing man-in-the-middle attacks.
Solution / Fix
National Rail Enquiries Live Departure Boards Gadget Remote Script Code Execution Vulnerability
Solution:
The vendor has released version 1.1 to address this issue. Please see the references for more information.
Solution:
The vendor has released version 1.1 to address this issue. Please see the references for more information.
References
National Rail Enquiries Live Departure Boards Gadget Remote Script Code Execution Vulnerability
References:
References:
- MWR InfoSecurity publish National Rail Windows Gadget Advisory (MWR InfoSecurity)
- National Rail Enquiries: Live Departure Boards Home Page (National Rails Enquiries)
- National Rail Live Enquiries Departure Board Gadget Vulnerability (MWR InfoSecurity)