Sophos Antivirus Configuration Console Multiple Cross Site Scripting Vulnerabilities
BID:68190
Info
Sophos Antivirus Configuration Console Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 68190 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2014 12:00AM |
| Updated: | Jun 24 2014 12:00AM |
| Credit: | Pablo Catalina |
| Vulnerable: |
Sophos Anti-Virus 9.5.1 |
| Not Vulnerable: | |
Discussion
Sophos Antivirus Configuration Console Multiple Cross Site Scripting Vulnerabilities
Sophos Antivirus is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Sophos Antivirus is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Sophos Antivirus Configuration Console Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Sophos Antivirus Configuration Console Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly, these issues are fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, these issues are fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Sophos Antivirus Configuration Console Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Sophos Homepage (Sophos)