NFlash Useradmin.CGI Script Code Injection Vulnerability
BID:7195
Info
NFlash Useradmin.CGI Script Code Injection Vulnerability
| Bugtraq ID: | 7195 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2003 12:00AM |
| Updated: | Mar 25 2003 12:00AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
Stefan Bethge nflash 0.7.1 Stefan Bethge nflash 0.7 |
| Not Vulnerable: | |
Discussion
NFlash Useradmin.CGI Script Code Injection Vulnerability
NFlash has been reported prone to script code injection vulnerabilities.
This is due to the lack of sanitization on user-supplied input, used to generate pages with dynamic content. An attacker may inject script code using several form fields or URI parameters of the NFlash user administration page.
When another user views one of these pages, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the vulnerable software.
It may be possible to steal an unsuspecting user's cookie-based authentication credentials, as well as other sensitive information. Other attacks are also possible.
NFlash has been reported prone to script code injection vulnerabilities.
This is due to the lack of sanitization on user-supplied input, used to generate pages with dynamic content. An attacker may inject script code using several form fields or URI parameters of the NFlash user administration page.
When another user views one of these pages, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the vulnerable software.
It may be possible to steal an unsuspecting user's cookie-based authentication credentials, as well as other sensitive information. Other attacks are also possible.
Exploit / POC
NFlash Useradmin.CGI Script Code Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
NFlash Useradmin.CGI Script Code Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
NFlash Useradmin.CGI Script Code Injection Vulnerability
References:
References:
- NFlash Homepage (Stefan Bethge)