Juniper ScreenOS HTML Injection Vulnerability
BID:31528
Info
Juniper ScreenOS HTML Injection Vulnerability
| Bugtraq ID: | 31528 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6096 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2008 12:00AM |
| Updated: | Apr 16 2015 05:53PM |
| Credit: | Deral Heiland |
| Vulnerable: |
Juniper Networks ScreenOS 5.4 r9.0 |
| Not Vulnerable: |
Juniper Networks ScreenOS 6.1 r2 Juniper Networks ScreenOS 6.0 r6 Juniper Networks ScreenOS 5.4 r10 |
Discussion
Juniper ScreenOS HTML Injection Vulnerability
ScreenOS is prone to an HTML-injection vulnerability because its administrative web interface fails to sufficiently sanitize user-supplied input data.
Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
The issue affects ScreenOS 5.4.0r9.0.
ScreenOS is prone to an HTML-injection vulnerability because its administrative web interface fails to sufficiently sanitize user-supplied input data.
Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
The issue affects ScreenOS 5.4.0r9.0.
Exploit / POC
Juniper ScreenOS HTML Injection Vulnerability
Attacker can exploit this issue using standard, readily available tools.
Attacker can exploit this issue using standard, readily available tools.
Solution / Fix
Juniper ScreenOS HTML Injection Vulnerability
Solution:
ScreenOS 5.4.0r10, 6.0.0r6, 6.1.0r2, and later versions are not affected by this issue. Please see the references and contact the vendor for more information.
Solution:
ScreenOS 5.4.0r10, 6.0.0r6, 6.1.0r2, and later versions are not affected by this issue. Please see the references and contact the vendor for more information.
References
Juniper ScreenOS HTML Injection Vulnerability
References:
References: