RemotelyAnywhere Autologon.HTML Password/Domain Cross-Site Scripting Vulnerability
BID:9120
Info
RemotelyAnywhere Autologon.HTML Password/Domain Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9120 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 27 2003 12:00AM |
| Updated: | Nov 27 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
RemotelyAnywhere RemotelyAnywhere Server Edition 5.10.416 RemotelyAnywhere RemotelyAnywhere Server Edition RemotelyAnywhere RemotelyAnywhere Personal Edition RemotelyAnywhere RemotelyAnywhere Enterprise Edition |
| Not Vulnerable: | |
Discussion
RemotelyAnywhere Autologon.HTML Password/Domain Cross-Site Scripting Vulnerability
RemotelyAnywhere has been reported prone to a cross-site scripting vulnerability that exists in the authentication interface. An attacker may exploit this condition, by crafting a malicious link to the RemotelyAnywhere service; the URL will contain script code embedded as values for the password or domain URI parameters.
RemotelyAnywhere has been reported prone to a cross-site scripting vulnerability that exists in the authentication interface. An attacker may exploit this condition, by crafting a malicious link to the RemotelyAnywhere service; the URL will contain script code embedded as values for the password or domain URI parameters.
Exploit / POC
RemotelyAnywhere Autologon.HTML Password/Domain Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
RemotelyAnywhere Autologon.HTML Password/Domain Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
RemotelyAnywhere Autologon.HTML Password/Domain Cross-Site Scripting Vulnerability
References:
References:
- Vendor Homepage (RemotelyAnywhere)