HP SiteScope Cross Site Scripting and HTML Injection Vulnerabilities
BID:47554
Info
HP SiteScope Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 47554 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1726 CVE-2011-1727 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2011 12:00AM |
| Updated: | May 04 2011 04:43PM |
| Credit: | HP |
| Vulnerable: |
HP SiteScope 9.54 HP SiteScope 11.1 HP SiteScope 11.01 HP SiteScope 10.13 |
| Not Vulnerable: | |
Discussion
HP SiteScope Cross Site Scripting and HTML Injection Vulnerabilities
HP SiteScope is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
HP SiteScope versions 9.54, 10.13, 11.01, and 11.1 are affected.
HP SiteScope is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
HP SiteScope versions 9.54, 10.13, 11.01, and 11.1 are affected.
Exploit / POC
HP SiteScope Cross Site Scripting and HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
HP SiteScope Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
HP SiteScope Cross Site Scripting and HTML Injection Vulnerabilities
References:
References: