Axon Virtual PBX 'logon' Multiple Cross Site Scripting Vulnerabilities
BID:41894
Info
Axon Virtual PBX 'logon' Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 41894 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4038 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2009 12:00AM |
| Updated: | Nov 11 2009 12:00AM |
| Credit: | Dejan Levaja |
| Vulnerable: |
NCH Software Axon 2.11 NCH Software Axon 2.10 |
| Not Vulnerable: |
NCH Software Axon 2.13 |
Discussion
Axon Virtual PBX 'logon' Multiple Cross Site Scripting Vulnerabilities
Axon Virtual PBX is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Axon 2.10 and 2.11 are vulnerable; other versions may also be affected.
Axon Virtual PBX is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Axon 2.10 and 2.11 are vulnerable; other versions may also be affected.
Exploit / POC
Axon Virtual PBX 'logon' Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Axon Virtual PBX 'logon' Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly these issues have been fixed in Axon 2.13. Please see the references for more information.
Solution:
Reportedly these issues have been fixed in Axon 2.13. Please see the references for more information.
References
Axon Virtual PBX 'logon' Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Axon Homepage (NCH Software)