Akamai Red Swoosh Client Web Server Cross-Site Request Forgery Vulnerability
BID:29587
Info
Akamai Red Swoosh Client Web Server Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 29587 |
| Class: | Design Error |
| CVE: |
CVE-2008-1106 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2008 12:00AM |
| Updated: | Jun 06 2008 12:00AM |
| Credit: | Dyon Balding, Secunia Research |
| Vulnerable: |
Akamai Red Swoosh Client 3322 |
| Not Vulnerable: |
Akamai Red Swoosh Client 3333 |
Discussion
Akamai Red Swoosh Client Web Server Cross-Site Request Forgery Vulnerability
Akamai Red Swoosh Client is prone to a cross-site request-forgery vulnerability.
Attackers can leverage this issue to transfer malicious data to a user's computer in the guise of a legitimate source. A successful exploit can aid in the compromise of affected computers; other attacks are also possible.
Versions prior to Red Swoosh Client 3333 are vulnerable.
Akamai Red Swoosh Client is prone to a cross-site request-forgery vulnerability.
Attackers can leverage this issue to transfer malicious data to a user's computer in the guise of a legitimate source. A successful exploit can aid in the compromise of affected computers; other attacks are also possible.
Versions prior to Red Swoosh Client 3333 are vulnerable.
Exploit / POC
Akamai Red Swoosh Client Web Server Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
Solution / Fix
Akamai Red Swoosh Client Web Server Cross-Site Request Forgery Vulnerability
Solution:
The vendor released Red Swoosh Client 3333 to address this issue. Please see the references for more information.
Akamai Red Swoosh Client 3322
Solution:
The vendor released Red Swoosh Client 3333 to address this issue. Please see the references for more information.
Akamai Red Swoosh Client 3322
-
Akamai rslin_3333
http://www.akapult.net/install/bin/rslin_3333 -
Akamai rsmac_3333
http://www.akapult.net/install/bin/rsmac_3333 -
Akamai rswin_3333.dll
http://www.akapult.net/install/bin/rswin_3333.dll
References
Akamai Red Swoosh Client Web Server Cross-Site Request Forgery Vulnerability
References:
References:
- Vendor Homepage (Akamai)
- Akamai Technologies Security Advisory 2008-0003 (Akamai Client Software) (Akamai Security Team
) - Secunia Research: Akamai Red Swoosh Cross-Site Request Forgery (Secunia Research
) - Secunia Research 06/06/2008 - Akamai Red Swoosh Cross-Site Request Forgery Vulne (Secunia Research)