Novell iChain Web Server Failed Login Page Cross-Site Scripting Vulnerability
BID:9412
Info
Novell iChain Web Server Failed Login Page Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9412 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2004 12:00AM |
| Updated: | Jan 13 2004 12:00AM |
| Credit: | The disclosure of this issue has been credited to the vendor. |
| Vulnerable: |
Novell iChain Server 2.2 SP1 Novell iChain Server 2.2 FP1a Novell iChain Server 2.2 FP1 Novell iChain Server 2.2 |
| Not Vulnerable: |
Novell iChain Server 2.2.113 |
Discussion
Novell iChain Web Server Failed Login Page Cross-Site Scripting Vulnerability
It has been reported that Novell iChain Server may be prone to a cross-site scripting vulnerability that may allow a remote user to launch cross-site scripting attacks. The problem is reported to exist due to improper sanitizing of user-supplied data in the 'url=' parameter passed to the failed login page.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
It has been reported that Novell iChain Server may be prone to a cross-site scripting vulnerability that may allow a remote user to launch cross-site scripting attacks. The problem is reported to exist due to improper sanitizing of user-supplied data in the 'url=' parameter passed to the failed login page.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
Novell iChain Web Server Failed Login Page Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Novell iChain Web Server Failed Login Page Cross-Site Scripting Vulnerability
Solution:
Novell has released Technical Information Document (TID2968872) and iChain 2.2 Support Pack 3 Beta 1; this support pack contains a fix to address this and other issues. Please see the referenced Technical Information Document for further details regarding obtaining and applying this support pack.
The vendor has reported that Novell iChain builds 2.2.113 and later are not prone to this issue. Users are advised to upgrade to the fixed versions by contacting the vendor.
Solution:
Novell has released Technical Information Document (TID2968872) and iChain 2.2 Support Pack 3 Beta 1; this support pack contains a fix to address this and other issues. Please see the referenced Technical Information Document for further details regarding obtaining and applying this support pack.
The vendor has reported that Novell iChain builds 2.2.113 and later are not prone to this issue. Users are advised to upgrade to the fixed versions by contacting the vendor.
References
Novell iChain Web Server Failed Login Page Cross-Site Scripting Vulnerability
References:
References:
- iChain Homepage (Novell)
- NESSUS scan results against iChain 2.2 - TID10080762 (Novell)
- TID2968872 - iChain 2.2 Support Pack 3 Beta 1 (Novell)