Sun Cobalt RaQ Service.CGI Cross Scripting Vulnerability
BID:4211
Info
Sun Cobalt RaQ Service.CGI Cross Scripting Vulnerability
| Bugtraq ID: | 4211 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0346 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability discovery credited to Alex Hernandez <[email protected]>. |
| Vulnerable: |
Cobalt RaQ 4.0 Cobalt RaQ 3.0 Cobalt RaQ 2.0 |
| Not Vulnerable: | |
Discussion
Sun Cobalt RaQ Service.CGI Cross Scripting Vulnerability
RaQ is a server appliance originally developed by Cobalt. It is now distributed and maintained by Sun Microsystems.
Due to insufficient sanitization of input, it is possible to execute script code on Cobalt RaQ systems. The problem occurs in the filtering of maliciously HTML tags when passed to the service.cgi and alert.cgi scripts. It has been reported that by passing malicious script code through the search.cgi or alert.cgi scripts, it may be possible to place malicious content on pages hosted by the RaQ server.
RaQ is a server appliance originally developed by Cobalt. It is now distributed and maintained by Sun Microsystems.
Due to insufficient sanitization of input, it is possible to execute script code on Cobalt RaQ systems. The problem occurs in the filtering of maliciously HTML tags when passed to the service.cgi and alert.cgi scripts. It has been reported that by passing malicious script code through the search.cgi or alert.cgi scripts, it may be possible to place malicious content on pages hosted by the RaQ server.
Exploit / POC
Sun Cobalt RaQ Service.CGI Cross Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sun Cobalt RaQ Service.CGI Cross Scripting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sun Cobalt RaQ Service.CGI Cross Scripting Vulnerability
References:
References: