[NEWS] SonicWall SOHO Cross Site Scripting and Arbitrary Code Injection
SecuriTeam <[email protected]>
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
SonicWall SOHO Cross Site Scripting and Arbitrary Code Injection
------------------------------------------------------------------------
SUMMARY
SonicWALL SOHO/10 "is a 2nd generation Internet Security Appliance from
SonicWALL, with firewall, VPN, content filtering and other capabilities".
Flaws in the user input validation functions makes SonicWALL SOHO/10
vulnerable to cross site scripting attacks and arbitrary code injection.
DETAILS
Vulnerable Systems:
* SonicWALL SOHO/10
- Firmware: 5.1.7.0
- ROM-Version: 4.0.0
An HTTP-GET-request, containing script code will be executed in the web
browsers environment of the user:
http://192.168.168.168/<script>alert("XSS")</script>
If an attacker supplies a username, via the uName parameter, containing
script code at the login-page of the device, an entry in the system log
file will be inserted containing the tainted "username".
As the system log file is displayed in HTML format, the administrator
viewing the log file will execute the injected script code.
As the length of the input field is limited by the browser (client side),
you can insert the following short script into the username field to do a
quick verification of this vulnerability:
</TD><script>alert("!")</script>
ADDITIONAL INFORMATION
The information has been provided by <mailto:[email protected]> Oliver
Karow.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected]
In order to subscribe to the mailing list, simply forward this email to: [email protected]
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.