Cyberoam UTM Multiple Cross Site Scripting Vulnerabilities
BID:48814
Info
Cyberoam UTM Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 48814 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2011 12:00AM |
| Updated: | Jul 20 2011 12:00AM |
| Credit: | Patrick Webster |
| Vulnerable: |
Elitecore Technologies Cyberoam UTM 10.01 build 0667 Elitecore Technologies Cyberoam UTM 10.00 build 0309 |
| Not Vulnerable: |
Elitecore Technologies Cyberoam UTM 10.01.0 Build 0739 |
Discussion
Cyberoam UTM Multiple Cross Site Scripting Vulnerabilities
Cyberoam UTM is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Cyberoam UTM is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Cyberoam UTM Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
Solution / Fix
Cyberoam UTM Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Cyberoam UTM Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Cyberoam UTM Homepage (Elitecore Technologies)
- Elitecore Cyberoam UTM - Authenticated Cross-Site Scripting Vulnerability (OSI Security Pty Ltd)
- OSI Security: Elitecore Cyberoam UTM - Authenticated Cross-Site (Patrick Webster)