Splunk HTTP 'Referer' Header Cross Site Scripting Vulnerability
BID:40930
Info
Splunk HTTP 'Referer' Header Cross Site Scripting Vulnerability
| Bugtraq ID: | 40930 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2010 12:00AM |
| Updated: | Jun 07 2010 12:00AM |
| Credit: | Patrik Nordlen |
| Vulnerable: |
Splunk Splunk 4.1.2 Splunk Splunk 4.1.1 Splunk Splunk 4.0 Splunk Splunk 4.1 |
| Not Vulnerable: |
Splunk Splunk 4.1.3 |
Exploit / POC
Splunk HTTP 'Referer' Header Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious page.
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious page.
Solution / Fix
Splunk HTTP 'Referer' Header Cross Site Scripting Vulnerability
Solution:
Updates are available. See the references for more details.
Solution:
Updates are available. See the references for more details.
References
Splunk HTTP 'Referer' Header Cross Site Scripting Vulnerability
References:
References:
- Splunk 4.1.3 Download (Splunk)
- Splunk Homepage (Splunk)
- Cross-Site Scripting in Splunk Web with 404 Responses in Internet Explorer - Jun (Splunk)