HeXHub Buffer Overflow And Cross-Site Scripting Vulnerabilities
BID:32479
Info
HeXHub Buffer Overflow And Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 32479 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2008 12:00AM |
| Updated: | Nov 26 2008 05:54PM |
| Credit: | HeXHub |
| Vulnerable: |
HeXHub HeXHub 5.02cFirewall1.09 |
| Not Vulnerable: | |
Discussion
HeXHub Buffer Overflow And Cross-Site Scripting Vulnerabilities
HeXHub is prone to a buffer-overflow vulnerability and a cross-site scripting vulnerability.
Successful exploits of buffer-overflow vulnerabilities may allow attackers to execute arbitrary code in the context of the application. This may result in a compromise of the underlying system. Failed attempts may lead to a denial-of-service condition.
Exploiting cross-site scripting vulnerabilities may allow an attacker to steal cookie-based information or execute script code in the context of the browser of an unsuspecting user.
Versions prior to HeXHub 5.02cFirewall1.09 are vulnerable.
HeXHub is prone to a buffer-overflow vulnerability and a cross-site scripting vulnerability.
Successful exploits of buffer-overflow vulnerabilities may allow attackers to execute arbitrary code in the context of the application. This may result in a compromise of the underlying system. Failed attempts may lead to a denial-of-service condition.
Exploiting cross-site scripting vulnerabilities may allow an attacker to steal cookie-based information or execute script code in the context of the browser of an unsuspecting user.
Versions prior to HeXHub 5.02cFirewall1.09 are vulnerable.
Exploit / POC
HeXHub Buffer Overflow And Cross-Site Scripting Vulnerabilities
An attacker can exploit the cross-site scripting issue by enticing an unsuspecting user to follow a malicious URI.
Currently we are not aware of any working exploits for the buffer-overflow issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker can exploit the cross-site scripting issue by enticing an unsuspecting user to follow a malicious URI.
Currently we are not aware of any working exploits for the buffer-overflow issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HeXHub Buffer Overflow And Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released fixes. Please see the references for more information.
HeXHub HeXHub 5.02cFirewall1.09
Solution:
The vendor has released fixes. Please see the references for more information.
HeXHub HeXHub 5.02cFirewall1.09
-
HeXHub EN_HeXHub_5.02cFirewall1.09.zip
http://downloads.sourceforge.net/hexhub/EN_HeXHub_5.02cFirewall1.09.zi p?modtime=1227427105&big_mirror=0
References
HeXHub Buffer Overflow And Cross-Site Scripting Vulnerabilities
References:
References:
- HeXHub HeXHub5.02cFirewall1.09 Release Notes (HeXHub)
- HeXHub Project Page (HeXHub)