FAST ESP Cross Site Scripting Vulnerability
BID:33750
Info
FAST ESP Cross Site Scripting Vulnerability
| Bugtraq ID: | 33750 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-5092 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2009 12:00AM |
| Updated: | Apr 13 2015 09:11PM |
| Credit: | Kentaro Ohshima |
| Vulnerable: |
FAST FAST ESP 5.1.5 |
| Not Vulnerable: | |
Discussion
FAST ESP Cross Site Scripting Vulnerability
FAST ESP is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
FAST ESP 5.1.5 is vulnerable; other versions may also be affected.
FAST ESP is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
FAST ESP 5.1.5 is vulnerable; other versions may also be affected.
Exploit / POC
FAST ESP Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
FAST ESP Cross Site Scripting Vulnerability
Solution:
Reportedly, the vendor released updates to address this issue, but Symantec has not confirmed this. Please see the references and contact the vendor for more information.
Solution:
Reportedly, the vendor released updates to address this issue, but Symantec has not confirmed this. Please see the references and contact the vendor for more information.