Fox DataDiode Proxy Server CVE-2014-2358 Cross Site Request Forgery Vulnerability
BID:70614
Info
Fox DataDiode Proxy Server CVE-2014-2358 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 70614 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2358 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2014 12:00AM |
| Updated: | Oct 16 2014 12:00AM |
| Credit: | Tudor Enache of HelpAG |
| Vulnerable: |
Fox IT Fox DataDiode Appliance 1.7.1 Fox IT Fox DataDiode Appliance 1.7 |
| Not Vulnerable: |
Fox IT Fox DataDiode Appliance 1.7.2 |
Discussion
Fox DataDiode Proxy Server CVE-2014-2358 Cross Site Request Forgery Vulnerability
Fox DataDiode proxy server is prone to a cross-site request-forgery vulnerability.
An attacker can leverage this issue to cause a denial-of-service condition.
Fox DataDiode Appliance 1.7.1 and prior are vulnerable.
Fox DataDiode proxy server is prone to a cross-site request-forgery vulnerability.
An attacker can leverage this issue to cause a denial-of-service condition.
Fox DataDiode Appliance 1.7.1 and prior are vulnerable.
Exploit / POC
Fox DataDiode Proxy Server CVE-2014-2358 Cross Site Request Forgery Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Fox DataDiode Proxy Server CVE-2014-2358 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Fox DataDiode Proxy Server CVE-2014-2358 Cross Site Request Forgery Vulnerability
References:
References: