Juniper Junos J-Web CVE-2014-2711 HTML Injection Vulnerability
BID:66770
Info
Juniper Junos J-Web CVE-2014-2711 HTML Injection Vulnerability
| Bugtraq ID: | 66770 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2711 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2014 12:00AM |
| Updated: | Apr 09 2014 12:00AM |
| Credit: | Chuck McAuley |
| Vulnerable: |
Juniper Junos 13.3 Juniper Junos 13.2R2-S2 Juniper Junos 13.2R2 Juniper Junos 13.2 Juniper Junos 13.1R3-S1 Juniper Junos 13.1R.3-S1 Juniper Junos 13.1 Juniper Junos 12.3R5 Juniper Junos 12.3R4-S3 Juniper Junos 12.3R4-S2 Juniper Junos 12.3 Juniper Junos 12.2R1 Juniper Junos 12.2 Juniper Junos 12.1X46-D10 Juniper Junos 12.1X46 Juniper Junos 12.1X45-D20 Juniper Junos 12.1X45-D10 Juniper Junos 12.1X45 Juniper Junos 12.1X44-D30 Juniper Junos 12.1X44-D26 Juniper Junos 12.1X44-D20 Juniper Junos 12.1X44 Juniper Junos 12.1R8-S3 Juniper Junos 12.1R8-S2 Juniper Junos 12.1R7 Juniper Junos 12.1R Juniper Junos 12.1 Juniper Junos 11.4X27 Juniper Junos 11.4R9 Juniper Junos 11.4R8 Juniper Junos 11.4R10-S1 Juniper Junos 11.4R10 Juniper Junos 11.4 Juniper Junos 11.4 |
| Not Vulnerable: |
Juniper Junos 13.3R1 Juniper Junos 13.2R3 Juniper Junos 13.1R4 Juniper Junos 12.3R6 Juniper Junos 12.2R7 Juniper Junos 12.1X46-D20 Juniper Junos 12.1X45-D25 Juniper Junos 12.1X44-D35 Juniper Junos 12.1R9 Juniper Junos 11.4X27.62 (BBE) Juniper Junos 11.4R11 |
Discussion
Juniper Junos J-Web CVE-2014-2711 HTML Injection Vulnerability
Juniper Junos is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Juniper Junos is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Exploit / POC
Juniper Junos J-Web CVE-2014-2711 HTML Injection Vulnerability
Attackers can exploit this issue using browser.
Attackers can exploit this issue using browser.
References
Juniper Junos J-Web CVE-2014-2711 HTML Injection Vulnerability
References:
References: