UseResponse Backdoor Unauthorized Access and HTML Injection Vulnerabilities
BID:54036
Info
UseResponse Backdoor Unauthorized Access and HTML Injection Vulnerabilities
| Bugtraq ID: | 54036 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2012 12:00AM |
| Updated: | Jun 15 2012 12:00AM |
| Credit: | mr_me |
| Vulnerable: |
UseResponse UseResponse 1.0.2 |
| Not Vulnerable: | |
Discussion
UseResponse Backdoor Unauthorized Access and HTML Injection Vulnerabilities
UseResponse is prone to an unauthorized-access vulnerability and an HTML-injection vulnerability.
An attacker may leverage these issues to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, or to gain unauthorized access to the affected application through backdoor. This may aid in further attacks.
UseResponse 1.0.2 is vulnerable; other versions may also be affected.
UseResponse is prone to an unauthorized-access vulnerability and an HTML-injection vulnerability.
An attacker may leverage these issues to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, or to gain unauthorized access to the affected application through backdoor. This may aid in further attacks.
UseResponse 1.0.2 is vulnerable; other versions may also be affected.
Solution / Fix
UseResponse Backdoor Unauthorized Access and HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].