acFreeProxy跨站脚本漏洞

acFreeProxy跨站脚本漏洞

漏洞ID 1203344 漏洞类型 跨站脚本
发布时间 2002-12-31 更新时间 2002-12-31
图片[1]-acFreeProxy跨站脚本漏洞-安全小百科CVE编号 CVE-2002-2418
图片[2]-acFreeProxy跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200212-463
漏洞平台 N/A CVSS评分 4.3
|漏洞来源
https://cxsecurity.com/issue/WLB-2007110001
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-463
|漏洞详情
acFreeProxy(akaacFP)1.33beta7版本存在跨站脚本(XSS)漏洞。远程攻击者借助URL注入任意web脚本或者HTML,该漏洞被插入到一个错误页面。
|漏洞EXP
Product Information

acFreeProxy (aka "acfp") is an HTTP/1.x proxy for Microsoft Windows
environments.  It offers caching, and several other features, and has a
plug-in format designed for extensibility.  A flaw in the product may allow
attackers to execute content across domains.

Description

The proxy server may generate an error message if given a host that it
cannot reach, or some other exceptional condition.  The error page generated
during this process does not have any input validation, and is vulnerable to
cross-site scripting.  This allows an attacker to inject code as *any site*
the victim can visit, because this problem is in the proxy, and not a
specific site.

Impact

This vulnerability is significantly more dangerous than any site-specific
flaw, as it can be exploited to read content from any domain, instead of the
limited scope of a typical cross-site scripting flaw, where the site that is
flawed is the only site that can be impacted.

Exploit

http://www.hotmail.com:41997/%3CSCRIPT%3Ealert%28document%3EURL%29%3C/SC
RIPT
%3E/

If a vulnerable proxy is being run, script execution begins.

I've also found bizarre crash behavior within acfp.  When it accesses
www.hotmail.com it crashes for some reason that I have yet to isolate.  I
believe that this may have something to do with empty entities in responses.
Any ideas?
|参考资料

来源:BID
名称:6236
链接:http://www.securityfocus.com/bid/6236
来源:XF
名称:acfp-error-page-xss(10682)
链接:http://www.iss.net/security_center/static/10682.php
来源:SREASON
名称:3327
链接:http://securityreason.com/securityalert/3327
来源:BUGTRAQ
名称:20021124acFreeProxyCross-SiteScriptingVulnerability/PossibleDoS
链接:http://online.securityfocus.com/archive/1/300925
来源:VULNWATCH
名称:20021123acFreeProxyCross-SiteScriptingVulnerability/PossibleDoS
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0089.html

相关推荐: FreeBSD exec() Inherited Signal Handler Vulnerability

FreeBSD exec() Inherited Signal Handler Vulnerability 漏洞ID 1103072 漏洞类型 Design Error 发布时间 2001-07-10 更新时间 2001-07-10 CVE编号 N/A CNN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享