ntop 'arbfile' Parameter Cross Site Scripting Vulnerability
BID:54792
Info
ntop 'arbfile' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 54792 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2012 12:00AM |
| Updated: | Aug 03 2012 12:00AM |
| Credit: | Marcos Garcia |
| Vulnerable: | |
| Not Vulnerable: | |
Exploit / POC
ntop 'arbfile' Parameter Cross Site Scripting Vulnerability
The following example URI is available:
http://www.example.com/plugins/rrdPlugin?action=arbreq&which=graph&arbfile=TEST">[XSS]&arbiface=eth0&start=1343344529&end=1343348129&counter=&title=Active+End+Nodes&mode=zoom
The following example URI is available:
http://www.example.com/plugins/rrdPlugin?action=arbreq&which=graph&arbfile=TEST">[XSS]&arbiface=eth0&start=1343344529&end=1343348129&counter=&title=Active+End+Nodes&mode=zoom
Solution / Fix
ntop 'arbfile' Parameter Cross Site Scripting Vulnerability
Solution:
Reportedly the issue is fixed; however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed; however Symantec has not confirmed this. Please contact the vendor for more information.