NetScreen-25 HTML Injection Log File Display Vulnerability
BID:4945
Info
NetScreen-25 HTML Injection Log File Display Vulnerability
| Bugtraq ID: | 4945 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2002 12:00AM |
| Updated: | Jun 05 2002 12:00AM |
| Credit: | Discovered by [email protected]. |
| Vulnerable: |
NetScreen ScreenOS 3.0.3 r1.1 |
| Not Vulnerable: | |
Discussion
NetScreen-25 HTML Injection Log File Display Vulnerability
NetScreen produces an event log HTML page which can be configured to itemize failed login attempts. This page is accessible through a web interface.
NetScreen fails to filter HTML tags from the authentication fields of the web user interface. As a result, the log files will appear as though they have been deleted.
This issue has been reported to exist in NetScreen-25 with ScreenOS 3.0.3r1.1, other versions may also be affected by this issue.
NetScreen produces an event log HTML page which can be configured to itemize failed login attempts. This page is accessible through a web interface.
NetScreen fails to filter HTML tags from the authentication fields of the web user interface. As a result, the log files will appear as though they have been deleted.
This issue has been reported to exist in NetScreen-25 with ScreenOS 3.0.3r1.1, other versions may also be affected by this issue.
Exploit / POC
NetScreen-25 HTML Injection Log File Display Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NetScreen-25 HTML Injection Log File Display Vulnerability
Solution:
Reportedly, the vendor has acknowledged this issue and will be addressing it in the next release of ScreenOS. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly, the vendor has acknowledged this issue and will be addressing it in the next release of ScreenOS. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
NetScreen-25 HTML Injection Log File Display Vulnerability
References:
References:
- NetScreen Homepage (NetScreen)