LemonLDAP:NG User Enumeration Weakness and Cross Site Scripting Vulnerability
BID:33312
Info
LemonLDAP:NG User Enumeration Weakness and Cross Site Scripting Vulnerability
| Bugtraq ID: | 33312 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2009 12:00AM |
| Updated: | Jan 19 2009 07:32PM |
| Credit: | Clément Oudot |
| Vulnerable: |
ObjectWeb Consortium LemonLDAP:NG 0.9.3.1 |
| Not Vulnerable: |
ObjectWeb Consortium LemonLDAP:NG 0.9.3.2 |
Discussion
LemonLDAP:NG User Enumeration Weakness and Cross Site Scripting Vulnerability
LemonLDAP:NG is prone to a user-enumeration weakness and a cross-site scripting vulnerability.
A remote attacker can exploit the user-enumeration weakness to enumerate valid usernames and then perform brute-force attacks; other attacks are also possible.
The attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to LemonLDAP::NG 0.9.3.2 are vulnerable.
LemonLDAP:NG is prone to a user-enumeration weakness and a cross-site scripting vulnerability.
A remote attacker can exploit the user-enumeration weakness to enumerate valid usernames and then perform brute-force attacks; other attacks are also possible.
The attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to LemonLDAP::NG 0.9.3.2 are vulnerable.
Exploit / POC
LemonLDAP:NG User Enumeration Weakness and Cross Site Scripting Vulnerability
An attacker can use brute-force techniques to exploit the user-enumeration weakness. To exploit the cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
An attacker can use brute-force techniques to exploit the user-enumeration weakness. To exploit the cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
Solution / Fix
LemonLDAP:NG User Enumeration Weakness and Cross Site Scripting Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
ObjectWeb Consortium LemonLDAP:NG 0.9.3.1
Solution:
The vendor released an update to address this issue. Please see the references for more information.
ObjectWeb Consortium LemonLDAP:NG 0.9.3.1
References
LemonLDAP:NG User Enumeration Weakness and Cross Site Scripting Vulnerability
References:
References:
- [lemonldap-ng-dev] Security issues (Clément Oudot)
- LemonLDAP:NG Homepage (ObjectWeb)