Advanced Research Security Auditor Research Assistant Service Banner HTML Injection Vulnerability
BID:9241
Info
Advanced Research Security Auditor Research Assistant Service Banner HTML Injection Vulnerability
| Bugtraq ID: | 9241 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2003 12:00AM |
| Updated: | Dec 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Thomas M. Payerle" <[email protected]>. |
| Vulnerable: |
Dan Farmer SATAN 1.1.1 Advanced Research Security Auditor's Research Assistant 4.2.7 Advanced Research Security Auditor's Research Assistant 4.2.6 Advanced Research Security Auditor's Research Assistant 4.2.5 Advanced Research Security Auditor's Research Assistant 4.2.1 |
| Not Vulnerable: |
Advanced Research Security Auditor's Research Assistant 5.0 |
Discussion
Advanced Research Security Auditor Research Assistant Service Banner HTML Injection Vulnerability
Advanced Research SARA has been reported prone to a HTML injection vulnerability. The issue has been reported to exist due to a lack of sufficient sanitization performed on banner data enumerated from remote services.
Successful exploitation of this issue may allow a remote attacker to steal cookie-based authentication credentials. Other attacks are possible as well. The impact of this issue may be exaggerated because the affected software invokes the web browser, and the software must be run as the root user.
Advanced Research SARA has been reported prone to a HTML injection vulnerability. The issue has been reported to exist due to a lack of sufficient sanitization performed on banner data enumerated from remote services.
Successful exploitation of this issue may allow a remote attacker to steal cookie-based authentication credentials. Other attacks are possible as well. The impact of this issue may be exaggerated because the affected software invokes the web browser, and the software must be run as the root user.
Exploit / POC
Advanced Research Security Auditor Research Assistant Service Banner HTML Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Advanced Research Security Auditor Research Assistant Service Banner HTML Injection Vulnerability
Solution:
The vendor has reportedly released an update to address this issue:
Advanced Research Security Auditor's Research Assistant 4.2.1
Advanced Research Security Auditor's Research Assistant 4.2.5
Advanced Research Security Auditor's Research Assistant 4.2.6
Advanced Research Security Auditor's Research Assistant 4.2.7
Solution:
The vendor has reportedly released an update to address this issue:
Advanced Research Security Auditor's Research Assistant 4.2.1
-
Advanced Research sara-5.0.0.tgz
http://www-arc.com/sara/downloads/sara-5.0.0.tgz
Advanced Research Security Auditor's Research Assistant 4.2.5
-
Advanced Research sara-5.0.0.tgz
http://www-arc.com/sara/downloads/sara-5.0.0.tgz
Advanced Research Security Auditor's Research Assistant 4.2.6
-
Advanced Research sara-5.0.0.tgz
http://www-arc.com/sara/downloads/sara-5.0.0.tgz
Advanced Research Security Auditor's Research Assistant 4.2.7
-
Advanced Research sara-5.0.0.tgz
http://www-arc.com/sara/downloads/sara-5.0.0.tgz
References
Advanced Research Security Auditor Research Assistant Service Banner HTML Injection Vulnerability
References:
References:
- SARA Homepage (Advanced Research)
- SATAN Homepage (Dan Farmer)
- Cross-site scripting vulnerability in SARA v<=4.2.7 ("Thomas M. Payerle"
) - Re: Cross-site scripting vulnerability in SARA v<=4.2.7 (
) - SARA 5.0 (
)