RaidenHTTPD Cross Site Scripting and Local File Include Vulnerabilities
BID:35781
Info
RaidenHTTPD Cross Site Scripting and Local File Include Vulnerabilities
| Bugtraq ID: | 35781 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2009 12:00AM |
| Updated: | Jul 24 2009 08:26PM |
| Credit: | Gama Sec |
| Vulnerable: |
RaidenHTTPD RaidenHTTPD 2.0.26 RaidenHTTPD RaidenHTTPD 2.0.25 RaidenHTTPD RaidenHTTPD 2.0.24 RaidenHTTPD RaidenHTTPD 2.0.23 RaidenHTTPD RaidenHTTPD 2.0.22 |
| Not Vulnerable: |
RaidenHTTPD RaidenHTTPD 2.0.27 |
Discussion
RaidenHTTPD Cross Site Scripting and Local File Include Vulnerabilities
RaidenHTTPD is prone to local file-include and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input. These issues affect the WebAdmin component.
A remote attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploiting the local file-include issue allows the attacker to view and subsequently execute local files within the context of the webserver process.
RaidenHTTPD 2.0 build 26 and prior versions are affected.
RaidenHTTPD is prone to local file-include and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input. These issues affect the WebAdmin component.
A remote attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploiting the local file-include issue allows the attacker to view and subsequently execute local files within the context of the webserver process.
RaidenHTTPD 2.0 build 26 and prior versions are affected.
Exploit / POC
RaidenHTTPD Cross Site Scripting and Local File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
RaidenHTTPD Cross Site Scripting and Local File Include Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
RaidenHTTPD Cross Site Scripting and Local File Include Vulnerabilities
References:
References:
- Changelog (RaidenHTTPD)
- RaidenHTTPD Homepage (RaidenHTTPD)