Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
BID:49069
Info
Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 49069 |
| Class: | Unknown |
| CVE: |
CVE-2011-2221 CVE-2011-2222 CVE-2011-2223 CVE-2011-2224 CVE-2011-2221 CVE-2011-2222 CVE-2011-2223 CVE-2011-2224 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2011 12:00AM |
| Updated: | Mar 19 2015 07:35AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Novell Data Synchronizer Mobility Pack 1.1.2 Novell Data Synchronizer Mobility Pack 1.1 Novell Data Synchronizer Mobility Pack 1.0 |
| Not Vulnerable: |
Novell Data Synchronizer Mobility Pack 1.2 |
Discussion
Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
Novell Data Synchronizer Mobility Pack is prone to multiple remote security vulnerabilities, including cross-site scripting, information-disclosure, and session-fixation issues.
Successful exploits of these vulnerabilities can allow attackers to execute arbitrary script code in a user's browser in the context of the webserver process, obtain sensitive data, or hijack a user's session.
Versions prior to Novell Data Synchronizer Mobility Pack 1.2 are vulnerable.
Novell Data Synchronizer Mobility Pack is prone to multiple remote security vulnerabilities, including cross-site scripting, information-disclosure, and session-fixation issues.
Successful exploits of these vulnerabilities can allow attackers to execute arbitrary script code in a user's browser in the context of the webserver process, obtain sensitive data, or hijack a user's session.
Versions prior to Novell Data Synchronizer Mobility Pack 1.2 are vulnerable.
Exploit / POC
Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
An attacker can exploit these issues using a browser. To exploit some of the issues, the attacker needs to entice a user to follow a malicious URI.
An attacker can exploit these issues using a browser. To exploit some of the issues, the attacker needs to entice a user to follow a malicious URI.
Solution / Fix
Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
References:
References:
- Novell Data Synchronizer (Novell)
- Novell Homepage (Novell)
- Cookie without HTTPOnly Flag Set (Novell)
- Password is exposed in UI and can be seen through a LAN Trace (Novell)
- Sensitive information revealed without authenticating to WebAdmin (Novell)
- Session Fixation with Webadmin (Novell)