IceWarp Server Multiple Cross Site Scripting Vulnerabilities
BID:47723
Info
IceWarp Server Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 47723 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2011 12:00AM |
| Updated: | May 05 2011 12:00AM |
| Credit: | Deniz Cevik and Biznet |
| Vulnerable: |
IceWarp IceWarp Server 10.2.1 IceWarp IceWarp Server 10.2 |
| Not Vulnerable: |
IceWarp IceWarp Server 10.3 |
Discussion
IceWarp Server Multiple Cross Site Scripting Vulnerabilities
IceWarp Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
IceWarp Server 10.2.x versions are vulnerable.
IceWarp Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
IceWarp Server 10.2.x versions are vulnerable.
Exploit / POC
IceWarp Server Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
IceWarp Server Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly, the vendor has released updates to address the issues; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has released updates to address the issues; however, Symantec has not confirmed this. Please contact the vendor for more information.