Fastream NetFile Error Message Cross-Site Scripting Vulnerability
BID:8908
Info
Fastream NetFile Error Message Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8908 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2003 12:00AM |
| Updated: | Oct 28 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Oliver Karow <[email protected]>. |
| Vulnerable: |
Fastream NetFile 6.0.3 .588 |
| Not Vulnerable: | |
Discussion
Fastream NetFile Error Message Cross-Site Scripting Vulnerability
It has been reported that a cross-site scripting vulnerability may exist in NetFile that may allow remote attackers to execute HTML or script code in a user's browser. The issue is reported to occur due to a "404 Not Found" error message returned to the user due to a request for a URL that does not exist. The error message reportedly contains the bad URL which is not properly sanitized therefore allowing an attacker to a construct a malicious link containing HTML or script code that may be rendered in a user's browser.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication information that could be used to launch further attacks.
NetFile FTP/Webserver Version 6.0.3.588 has been reported to be prone to this issue, however other versions may be affected as well.
It has been reported that a cross-site scripting vulnerability may exist in NetFile that may allow remote attackers to execute HTML or script code in a user's browser. The issue is reported to occur due to a "404 Not Found" error message returned to the user due to a request for a URL that does not exist. The error message reportedly contains the bad URL which is not properly sanitized therefore allowing an attacker to a construct a malicious link containing HTML or script code that may be rendered in a user's browser.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication information that could be used to launch further attacks.
NetFile FTP/Webserver Version 6.0.3.588 has been reported to be prone to this issue, however other versions may be affected as well.
Exploit / POC
Fastream NetFile Error Message Cross-Site Scripting Vulnerability
The following proof of concept has been provided:
http://www.example.com/<script>alert("bang")</script>
The following proof of concept has been provided:
http://www.example.com/<script>alert("bang")</script>
Solution / Fix
Fastream NetFile Error Message Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Fastream NetFile Error Message Cross-Site Scripting Vulnerability
References:
References:
- NetFile Product Page (Fastream)
- Fastream NetFile FTP/WebServer 6.0 CSS Vulnerability ("Oliver Karow"
)