Infinity CGI Exploit Scanner Cross-Site Scripting Vulnerability
BID:7910
Info
Infinity CGI Exploit Scanner Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7910 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2003 12:00AM |
| Updated: | Jun 12 2003 12:00AM |
| Credit: | Discovery of this issue is credited to badpack3t <[email protected]>. |
| Vulnerable: |
The Infinity Project Infinity CGI Exploit Scanner 3.11 Beta Exploit Labs Wood's InfinityScan EZ 3.69 |
| Not Vulnerable: | |
Discussion
Infinity CGI Exploit Scanner Cross-Site Scripting Vulnerability
Infinity CGI Exploit Scanner is reported to be prone to a cross-site scripting vulnerability. An attacker could exploit this issue to creating a malicious link to a site hosting the software that contains hostile HTML and script code. If this link is visited by a web user, the attacker-supplied code could be interpreted in their browser.
Infinity CGI Exploit Scanner is reported to be prone to a cross-site scripting vulnerability. An attacker could exploit this issue to creating a malicious link to a site hosting the software that contains hostile HTML and script code. If this link is visited by a web user, the attacker-supplied code could be interpreted in their browser.
Exploit / POC
Infinity CGI Exploit Scanner Cross-Site Scripting Vulnerability
The following example was submitted:
http://www.example.com/cgi-bin/nph-exploitscanget.cgi?host=%3Cscript%3Ealert%28document%2Ecookie%29%3C%2Fscript%3E&port=80&idsbypass=0&errchk=1
The following example was submitted:
http://www.example.com/cgi-bin/nph-exploitscanget.cgi?host=%3Cscript%3Ealert%28document%2Ecookie%29%3C%2Fscript%3E&port=80&idsbypass=0&errchk=1
Solution / Fix
Infinity CGI Exploit Scanner Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Infinity CGI Exploit Scanner Cross-Site Scripting Vulnerability
References:
References:
- Exploit Labs Homepage (Exploit Labs)