AIST Netcat 3.1.2 Multiple Input Validation Vulnerabilities
BID:32992
Info
AIST Netcat 3.1.2 Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 32992 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5730 CVE-2008-5742 CVE-2008-5728 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2008 12:00AM |
| Updated: | Jul 06 2016 02:18PM |
| Credit: | s4avrd0w |
| Vulnerable: |
AIST NetCat 3.12 |
| Not Vulnerable: | |
Discussion
AIST Netcat 3.1.2 Multiple Input Validation Vulnerabilities
AIST Netcat is prone to multiple input-validation vulnerabilities:
- Multiple local file-include vulnerabilities
- Multiple cross-site scripting vulnerabilities
- Multiple HTTP response-splitting vulnerabilities
- A CRLF-injection vulnerability
Attackers can exploit these issues to compromise the affected application; misrepresent how web content is served, cached, or interpreted; execute arbitrary script code and PHP code within the context of the webserver process; and obtain sensitive information. Other attacks are also possible.
AIST Netcat 3.1.2 is vulnerable; other versions may also be affected.
AIST Netcat is prone to multiple input-validation vulnerabilities:
- Multiple local file-include vulnerabilities
- Multiple cross-site scripting vulnerabilities
- Multiple HTTP response-splitting vulnerabilities
- A CRLF-injection vulnerability
Attackers can exploit these issues to compromise the affected application; misrepresent how web content is served, cached, or interpreted; execute arbitrary script code and PHP code within the context of the webserver process; and obtain sensitive information. Other attacks are also possible.
AIST Netcat 3.1.2 is vulnerable; other versions may also be affected.
Exploit / POC
AIST Netcat 3.1.2 Multiple Input Validation Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI
The following example URIs are available:
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI
The following example URIs are available:
Solution / Fix
AIST Netcat 3.1.2 Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].