Splunk Cross Site Scripting and Directory Traversal Vulnerabilities
BID:41269
Info
Splunk Cross Site Scripting and Directory Traversal Vulnerabilities
| Bugtraq ID: | 41269 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2010 12:00AM |
| Updated: | Jun 30 2010 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Splunk Splunk 4.1.1 Splunk Splunk 4.0.10 Splunk Splunk 4.0.9 Splunk Splunk 4.0.8 Splunk Splunk 4.0.7 Splunk Splunk 4.0.6 Splunk Splunk 4.0.5 Splunk Splunk 4.0.4 Splunk Splunk 4.0.3 Splunk Splunk 4.0.2 Splunk Splunk 4.0.1 Splunk Splunk 4.0 Splunk Splunk 4.1 Splunk Splunk 4 |
| Not Vulnerable: |
Splunk Splunk 4.0.11 |
Discussion
Splunk Cross Site Scripting and Directory Traversal Vulnerabilities
Splunk is prone to multiple cross-site scripting vulnerabilities and multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues will allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, and to view arbitrary local files and directories within the context of the webserver. This may let the attacker steal cookie-based authentication credentials and other harvested information may aid in launching further attacks.
Splunk is prone to multiple cross-site scripting vulnerabilities and multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues will allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, and to view arbitrary local files and directories within the context of the webserver. This may let the attacker steal cookie-based authentication credentials and other harvested information may aid in launching further attacks.
Exploit / POC
Splunk Cross Site Scripting and Directory Traversal Vulnerabilities
Attackers can exploit the cross-site scripting issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit the cross-site scripting issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Splunk Cross Site Scripting and Directory Traversal Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Splunk Splunk 4
Splunk Splunk 4.0
Splunk Splunk 4.0.1
Splunk Splunk 4.0.10
Splunk Splunk 4.0.2
Splunk Splunk 4.0.3
Splunk Splunk 4.0.4
Splunk Splunk 4.0.5
Splunk Splunk 4.0.6
Splunk Splunk 4.0.7
Splunk Splunk 4.0.8
Splunk Splunk 4.0.9
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Splunk Splunk 4
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.1
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.10
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.2
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.3
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.4
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.5
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.6
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.7
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.8
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
Splunk Splunk 4.0.9
-
Splunk splunk-patch-2010-001.bin
http://download.splunk.com/support/patch/splunk-patch-2010-001.bin
References
Splunk Cross Site Scripting and Directory Traversal Vulnerabilities
References:
References:
- Splunk Critical Maintainence Pack - May 3 2010 (Splunk)
- Splunk Homepage (Splunk)