FreeNAS Unspecified Cross Site Scripting Vulnerability
BID:36146
Info
FreeNAS Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 36146 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2739 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2009 12:00AM |
| Updated: | Aug 25 2009 10:02PM |
| Credit: | Hiroyuki Shinshiba of LAC:Little eArth Corporation Co., LTD. |
| Vulnerable: |
FreeNAS FreeNAS 0.69.1 FreeNAS FreeNAS 0.69RC2 FreeNAS FreeNAS 0.69 |
| Not Vulnerable: |
FreeNAS FreeNAS 0.69.2 |
Discussion
FreeNAS Unspecified Cross Site Scripting Vulnerability
FreeNAS is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to FreeNAS 0.69.2 are affected.
FreeNAS is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to FreeNAS 0.69.2 are affected.
Exploit / POC
FreeNAS Unspecified Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
FreeNAS Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
FreeNAS Unspecified Cross Site Scripting Vulnerability
References:
References: