Juniper IDP Appliance Configuration Manager Unspecified Cross Site Scripting Vulnerability
BID:49498
Info
Juniper IDP Appliance Configuration Manager Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 49498 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-5086 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2011 12:00AM |
| Updated: | May 09 2011 12:00AM |
| Credit: | Davy Douhine |
| Vulnerable: |
Juniper IDP 4.2 Juniper IDP 4.1r2 Juniper IDP 4.1 |
| Not Vulnerable: |
Juniper IDP 4.2r1 Juniper IDP 4.1r3 |
Discussion
Juniper IDP Appliance Configuration Manager Unspecified Cross Site Scripting Vulnerability
Juniper IDP Appliance Configuration Manager are prone to a cross-site scripting vulnerability because the devices' web interface fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following products are affected:
Juniper IDP 4.1 versions prior to 4.1r3
Juniper IDP 4.2 versions prior to 4.2r1
Juniper IDP Appliance Configuration Manager are prone to a cross-site scripting vulnerability because the devices' web interface fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following products are affected:
Juniper IDP 4.1 versions prior to 4.1r3
Juniper IDP 4.2 versions prior to 4.2r1
Exploit / POC
Juniper IDP Appliance Configuration Manager Unspecified Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Juniper IDP Appliance Configuration Manager Unspecified Cross Site Scripting Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
Juniper IDP Appliance Configuration Manager Unspecified Cross Site Scripting Vulnerability
References:
References:
- Juniper Networks Homepage (Juniper Networks)
- View Bulletin PSN-2009-01-191 (Juniper)