Alteon OS BBI Cross Site Request Forgery and HTML Injection Vulnerabilities
BID:37030
Info
Alteon OS BBI Cross Site Request Forgery and HTML Injection Vulnerabilities
| Bugtraq ID: | 37030 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2009 12:00AM |
| Updated: | Nov 16 2009 08:26PM |
| Credit: | Sintsov Alexey from Digital Security Research Group |
| Vulnerable: |
Alteon OS BBI 25.0.0.0 Alteon OS BBI 21.0.8.3 |
| Not Vulnerable: | |
Discussion
Alteon OS BBI Cross Site Request Forgery and HTML Injection Vulnerabilities
Alteon OS BBI (Browser Based Interface) is prone to a cross-site request-forgery vulnerability and multiple HTML-injection vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Alteon OS BBI (Browser Based Interface) is prone to a cross-site request-forgery vulnerability and multiple HTML-injection vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
Alteon OS BBI Cross Site Request Forgery and HTML Injection Vulnerabilities
An attacker can exploit HTML-injection issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
The following proofs of concept are available:
An attacker can exploit HTML-injection issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
The following proofs of concept are available:
Solution / Fix
Alteon OS BBI Cross Site Request Forgery and HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Alteon OS BBI Cross Site Request Forgery and HTML Injection Vulnerabilities
References:
References:
- Nortel Networks Homepage (Nortel Networks)
- Radware Homepage (Radware)
- [DSECRG-09-062] Alteon OS BBI (Nortell) - Multiple Vulnerabilities (DSecRG
)