Ajenti Multiple Cross Site Scripting Vulnerabilities
BID:68047
Info
Ajenti Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 68047 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-4301 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2014 12:00AM |
| Updated: | Oct 15 2014 12:01AM |
| Credit: | Netsparker |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Ajenti Multiple Cross Site Scripting Vulnerabilities
Ajenti is prone to multiple cross-site scripting vulnerabilities.
Attacker-supplied JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and control how the site is rendered to the user; other attacks are also possible.
Ajenti 1.2.21.6 is vulnerable; other versions may also be affected.
Ajenti is prone to multiple cross-site scripting vulnerabilities.
Attacker-supplied JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and control how the site is rendered to the user; other attacks are also possible.
Ajenti 1.2.21.6 is vulnerable; other versions may also be affected.
Exploit / POC
Ajenti Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Ajenti Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Ajenti Multiple Cross Site Scripting Vulnerabilities
References:
References: