Snare for Linux Multiple Security Vulnerabilities
BID:56883
Info
Snare for Linux Multiple Security Vulnerabilities
| Bugtraq ID: | 56883 |
| Class: | Unknown |
| CVE: |
CVE-2011-5250 CVE-2011-5249 CVE-2011-5247 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2011 12:00AM |
| Updated: | Aug 09 2011 12:00AM |
| Credit: | Andrew Brooks |
| Vulnerable: |
Intersect Alliance Snare for Linux 0 |
| Not Vulnerable: |
Intersect Alliance Snare for Linux 1.7 |
Discussion
Snare for Linux Multiple Security Vulnerabilities
Snare for Linux is prone to multiple security vulnerabilities including:
1. A cross-site request-forgery vulnerability
2. An information-disclosure vulnerability
3. A cross-site scripting vulnerability
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, perform unauthorized actions in the context of a user's session, or perform unauthorized actions. Other attacks are also possible.
Snare for Linux 1.7.0 prior versions are vulnerable.
Snare for Linux is prone to multiple security vulnerabilities including:
1. A cross-site request-forgery vulnerability
2. An information-disclosure vulnerability
3. A cross-site scripting vulnerability
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, perform unauthorized actions in the context of a user's session, or perform unauthorized actions. Other attacks are also possible.
Snare for Linux 1.7.0 prior versions are vulnerable.
Exploit / POC
Snare for Linux Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can exploit these issues through a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
Snare for Linux Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.