eFront Multiple Cross Site Scripting Vulnerabilities
BID:50469
Info
eFront Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 50469 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2011 12:00AM |
| Updated: | Nov 01 2011 12:00AM |
| Credit: | Netsparker Advisories |
| Vulnerable: |
eFront eFront 3.6.10 Build 11944 |
| Not Vulnerable: |
eFront eFront 3.6.10 Build 12151 |
Discussion
eFront Multiple Cross Site Scripting Vulnerabilities
eFront is prone to multiple cross-site scripting vulnerabilities because the software fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
eFront 3.6.10 build 11944 is vulnerable; other versions may also be affected.
eFront is prone to multiple cross-site scripting vulnerabilities because the software fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
eFront 3.6.10 build 11944 is vulnerable; other versions may also be affected.
Exploit / POC
eFront Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
Solution / Fix
eFront Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
eFront Multiple Cross Site Scripting Vulnerabilities
References:
References:
- eFront Homepage (eFront)
- XSS Vulnerabilities in eFront (Netsparker Advisories)