Proofpoint Protection Server 'process.cgi' Cross Site Scripting Vulnerability
BID:47687
Info
Proofpoint Protection Server 'process.cgi' Cross Site Scripting Vulnerability
| Bugtraq ID: | 47687 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2011 12:00AM |
| Updated: | May 03 2011 12:00AM |
| Credit: | Karan Khosla - Sense of Security Labs |
| Vulnerable: |
Proofpoint, Inc Proofpoint Protection Server 5.5.5 |
| Not Vulnerable: | |
Discussion
Proofpoint Protection Server 'process.cgi' Cross Site Scripting Vulnerability
Proofpoint Protection Server is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Proofpoint Protection Server 5.5.5 is vulnerable; other versions may also be affected.
Proofpoint Protection Server is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Proofpoint Protection Server 5.5.5 is vulnerable; other versions may also be affected.
Exploit / POC
Proofpoint Protection Server 'process.cgi' Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
http://www.example.com:10020/enduser/process.cgi?cmd=release&;
recipient=xxx () yyy com au&
msg_id=%28MDYzMjU0NTJkYTQ0OWRhYjJlNWY1MjBhNzc5MDEwODlkZGY5OGIzMTc1MGI=%29&
locale=enus&x=580&y=470&displayprogress=t%22%20
onmouseover=%22alert%281%29%22%20name=%22frame_display%22%20id=%22
frame_display%22%20NORESIZE%20SCROLLING=%22no%22%20/%3E%3C!--
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
http://www.example.com:10020/enduser/process.cgi?cmd=release&;
recipient=xxx () yyy com au&
msg_id=%28MDYzMjU0NTJkYTQ0OWRhYjJlNWY1MjBhNzc5MDEwODlkZGY5OGIzMTc1MGI=%29&
locale=enus&x=580&y=470&displayprogress=t%22%20
onmouseover=%22alert%281%29%22%20name=%22frame_display%22%20id=%22
frame_display%22%20NORESIZE%20SCROLLING=%22no%22%20/%3E%3C!--
Solution / Fix
Proofpoint Protection Server 'process.cgi' Cross Site Scripting Vulnerability
Solution:
Reportedly, the issue is fixed in patch 1084; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed in patch 1084; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Proofpoint Protection Server 'process.cgi' Cross Site Scripting Vulnerability
References:
References:
- Proofpoint Protection Server Cross-Site Scripting - Security Advisory - SOS-11- (Sense of Security)
- Proofpoint Protection Server Homepage (Proofpoint, Inc)