Xerox WorkCentre Unspecified HTML Injection Vulnerability
BID:29345
Info
Xerox WorkCentre Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 29345 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6436 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Henri Lindberg, Louhi Networks |
| Vulnerable: |
Xerox WorkCentre 7245 Xerox WorkCentre 7235 Xerox WorkCentre 7228 Xerox WorkCentre 7132 |
| Not Vulnerable: | |
Discussion
Xerox WorkCentre Unspecified HTML Injection Vulnerability
Xerox WorkCentre Web Server is prone to an unspecified HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
The following Xerox WorkCentre versions are affected:
WorkCentre 7132
WorkCentre 7228
WorkCentre 7235
WorkCentre 7245
Xerox WorkCentre Web Server is prone to an unspecified HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
The following Xerox WorkCentre versions are affected:
WorkCentre 7132
WorkCentre 7228
WorkCentre 7235
WorkCentre 7245
Exploit / POC
Xerox WorkCentre Unspecified HTML Injection Vulnerability
Attackers would likely exploit this issue via a browser.
Attackers would likely exploit this issue via a browser.
Solution / Fix
Xerox WorkCentre Unspecified HTML Injection Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Xerox WorkCentre Unspecified HTML Injection Vulnerability
References:
References:
- Xerox Homepage (Xerox)
- Xerox Security Bulletin XRX08-004 (Xerox)