LunarNight Laboratory WebProxy Cross Site Scripting Vulnerability
BID:30283
Info
LunarNight Laboratory WebProxy Cross Site Scripting Vulnerability
| Bugtraq ID: | 30283 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3255 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2008 12:00AM |
| Updated: | May 07 2015 05:27PM |
| Credit: | JVN |
| Vulnerable: |
LunarNight Laboratory WebProxy 1.7.8 LunarNight Laboratory WebProxy 1.7.7 LunarNight Laboratory WebProxy 1.7.6 LunarNight Laboratory WebProxy 1.7.5 LunarNight Laboratory WebProxy 1.7.4 LunarNight Laboratory WebProxy 1.7.3 LunarNight Laboratory WebProxy 1.7.2 LunarNight Laboratory WebProxy 1.7.1 LunarNight Laboratory WebProxy 1.7 |
| Not Vulnerable: |
LunarNight Laboratory WebProxy 1.7.9 |
Discussion
LunarNight Laboratory WebProxy Cross Site Scripting Vulnerability
LunarNight Laboratory WebProxy is prone to a cross-site scripting vulnerability.
Attacker-supplied HTML and script code may be injected into a user's browser session in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to LunarNight Laboratory WebProxy 1.7.9 are vulnerable.
LunarNight Laboratory WebProxy is prone to a cross-site scripting vulnerability.
Attacker-supplied HTML and script code may be injected into a user's browser session in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to LunarNight Laboratory WebProxy 1.7.9 are vulnerable.
Exploit / POC
LunarNight Laboratory WebProxy Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Solution / Fix
LunarNight Laboratory WebProxy Cross Site Scripting Vulnerability
Solution:
The vendor has released a fix. Please see the references for more information.
Solution:
The vendor has released a fix. Please see the references for more information.
References
LunarNight Laboratory WebProxy Cross Site Scripting Vulnerability
References:
References:
- LunarNight Laboratory Homepage (LunarNight Laboratory)
- WebProxy Release Notes (LunarNight Laboratory)