Cerberus FTP Server Web Admin Multiple HTML-Injection Vulnerabilities
BID:56906
Info
Cerberus FTP Server Web Admin Multiple HTML-Injection Vulnerabilities
| Bugtraq ID: | 56906 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-6339 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2012 12:00AM |
| Updated: | Dec 19 2012 11:20PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Cerberus FTP Server 4.0.3 0 Cerberus FTP Server 4.0.2 2 |
| Not Vulnerable: | |
Discussion
Cerberus FTP Server Web Admin Cross Site Scripting Vulnerability
Cerberus FTP Server is prone to a cross-site scripting vulnerability because it fails to properly sanitize certain user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Cerberus FTP Server versions prior to 5.0.6.0 are vulnerable.
Cerberus FTP Server is prone to a cross-site scripting vulnerability because it fails to properly sanitize certain user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Cerberus FTP Server versions prior to 5.0.6.0 are vulnerable.
Exploit / POC
Cerberus FTP Server Web Admin Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Cerberus FTP Server Web Admin Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Cerberus FTP Server Web Admin Multiple HTML-Injection Vulnerabilities
References:
References: