CacheFlow CacheOS Unresolved Domain Cross Site Scripting Vulnerability
BID:5305
Info
CacheFlow CacheOS Unresolved Domain Cross Site Scripting Vulnerability
| Bugtraq ID: | 5305 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2002 12:00AM |
| Updated: | Jul 24 2002 12:00AM |
| Credit: | Reported by "T.Suzuki" <[email protected]>. |
| Vulnerable: |
CacheFlow CacheOS 4.1 .06 CacheFlow CacheOS 4.0.14 CacheFlow CacheOS 4.0.13 CacheFlow CacheOS 4.0.12 CacheFlow CacheOS 4.0.11 CacheFlow CacheOS 4.0 CacheFlow CacheOS 3.1.21 CacheFlow CacheOS 3.1.19 CacheFlow CacheOS 3.1.18 CacheFlow CacheOS 3.1.17 |
| Not Vulnerable: |
CacheFlow CacheOS 4.1 .07 |
Discussion
CacheFlow CacheOS Unresolved Domain Cross Site Scripting Vulnerability
CacheOS is the firmware designed and distributed with CacheFlow web cache systems. It is maintained and distributed by CacheFlow.
User supplied data is not sanitized before being included in an unresolved host error page. An attacker may construct a link for a nonexistant subdomain of a valid site, and include malicious JavaScript. If followed, the supplied script code will execute within the context of the requested domain.
CacheOS is the firmware designed and distributed with CacheFlow web cache systems. It is maintained and distributed by CacheFlow.
User supplied data is not sanitized before being included in an unresolved host error page. An attacker may construct a link for a nonexistant subdomain of a valid site, and include malicious JavaScript. If followed, the supplied script code will execute within the context of the requested domain.
Exploit / POC
CacheFlow CacheOS Unresolved Domain Cross Site Scripting Vulnerability
No exploit is required. The following example is provided by "T.Suzuki" <[email protected]>:
http://dummy.example.com/<script>EVIL CODE</script>
No exploit is required. The following example is provided by "T.Suzuki" <[email protected]>:
http://dummy.example.com/<script>EVIL CODE</script>
Solution / Fix
CacheFlow CacheOS Unresolved Domain Cross Site Scripting Vulnerability
Solution:
This issue is resolved in CacheOS 4.1.07. Customers should contact the vendor for an updated version.
Solution:
This issue is resolved in CacheOS 4.1.07. Customers should contact the vendor for an updated version.
References
CacheFlow CacheOS Unresolved Domain Cross Site Scripting Vulnerability
References:
References:
- CacheFlow Homepage (CacheFlow)
- CacheOS Fixes for CA v4.1.07 (CacheFlow)