Veridis OpenKeyServer Cross Site Scripting Vulnerability
BID:4369
Info
Veridis OpenKeyServer Cross Site Scripting Vulnerability
| Bugtraq ID: | 4369 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2002 12:00AM |
| Updated: | Mar 26 2002 12:00AM |
| Credit: | Credited to SecurITeam Experts <[email protected]>. |
| Vulnerable: |
Veridis OpenKeyServer 1.2 |
| Not Vulnerable: | |
Discussion
Veridis OpenKeyServer Cross Site Scripting Vulnerability
Veridis OpenKeyServer is a public key repository for PGP based encryption. It supports a web interface for clients and synchronization with other key servers. It is available for Linux, FreeBSD, Solaris and Mac OS X.
A vulnerablity has been reported in the web interface used by OpenKeyServer. Certain pages are constructed which include user supplied data, opening a cross site scripting vulnerability.
Veridis OpenKeyServer is a public key repository for PGP based encryption. It supports a web interface for clients and synchronization with other key servers. It is available for Linux, FreeBSD, Solaris and Mac OS X.
A vulnerablity has been reported in the web interface used by OpenKeyServer. Certain pages are constructed which include user supplied data, opening a cross site scripting vulnerability.
Exploit / POC
Veridis OpenKeyServer Cross Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Veridis OpenKeyServer Cross Site Scripting Vulnerability
Solution:
Veridis has announced that they are working on a solution. The release date is not known at this time.
If you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Veridis has announced that they are working on a solution. The release date is not known at this time.
If you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Veridis OpenKeyServer Cross Site Scripting Vulnerability
References:
References:
- Keyservers Cross Site Scripting (When CSS Gets Dangerous) (Beyond Security Ltd.)
- OpenKeyServer Homepage (Veridis)