IBM Lotus Notes Traveler Multiple Input Validation Vulnerabilities
BID:55740
Info
IBM Lotus Notes Traveler Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 55740 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2012 12:00AM |
| Updated: | Sep 28 2012 12:00AM |
| Credit: | Eugene Dokukin aka MustLive |
| Vulnerable: |
IBM Lotus Notes Traveler 8.5.1.3 IBM Lotus Notes Traveler 8.5.1.2 IBM Lotus Notes Traveler 8.5.1.1 IBM Lotus Notes Traveler 8.5.1.0 |
| Not Vulnerable: |
IBM Lotus Notes Traveler 8.5.3 2 |
Discussion
IBM Lotus Notes Traveler Multiple Input Validation Vulnerabilities
IBM Lotus Notes Traveler is prone to a URI-redirection vulnerability, multiple HTML-injection vulnerabilities, and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to conduct phishing attacks. Other attacks are also possible.
IBM Lotus Notes Traveler 8.5.3 and prior are vulnerable; other versions may also be affected.
IBM Lotus Notes Traveler is prone to a URI-redirection vulnerability, multiple HTML-injection vulnerabilities, and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to conduct phishing attacks. Other attacks are also possible.
IBM Lotus Notes Traveler 8.5.3 and prior are vulnerable; other versions may also be affected.
Exploit / POC
IBM Lotus Notes Traveler Multiple Input Validation Vulnerabilities
An attacker must trick an unsuspecting victim into following a malicious URI to exploit the URI redirection and cross-site scripting issues. An attacker can exploit the HTML-injection issues through a browser.
The following example URIs are available:
http://www.example.com/servlet/traveler?deviceType=700&redirectURL=javascript:alert(document.cookie)
http://www.example.com/servlet/traveler?deviceType=700&redirectURL=data:text/html;base64,PHNjcmlwdD5hbGVydChkb2N1bWVudC5jb29raWUpPC9zY3JpcHQ%2B
http://www.example.com/servlet/traveler?deviceType=700&redirectURL=http://websecurity.com.ua
An attacker must trick an unsuspecting victim into following a malicious URI to exploit the URI redirection and cross-site scripting issues. An attacker can exploit the HTML-injection issues through a browser.
The following example URIs are available:
http://www.example.com/servlet/traveler?deviceType=700&redirectURL=javascript:alert(document.cookie)
http://www.example.com/servlet/traveler?deviceType=700&redirectURL=data:text/html;base64,PHNjcmlwdD5hbGVydChkb2N1bWVudC5jb29raWUpPC9zY3JpcHQ%2B
http://www.example.com/servlet/traveler?deviceType=700&redirectURL=http://websecurity.com.ua
Solution / Fix
IBM Lotus Notes Traveler Multiple Input Validation Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM Lotus Notes Traveler Multiple Input Validation Vulnerabilities
References:
References: