[NEWS] SonicWall SOHO Cross Site Scripting and Arbitrary Code Injection

SecuriTeam <[email protected]>
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  SonicWall SOHO Cross Site Scripting and Arbitrary Code Injection
------------------------------------------------------------------------


SUMMARY

SonicWALL SOHO/10 "is a 2nd generation Internet Security Appliance from 
SonicWALL, with firewall, VPN, content filtering and other capabilities".

Flaws in the user input validation functions makes SonicWALL SOHO/10 
vulnerable to cross site scripting attacks and arbitrary code injection.

DETAILS

Vulnerable Systems:
 * SonicWALL SOHO/10
 - Firmware: 5.1.7.0
 - ROM-Version: 4.0.0

An HTTP-GET-request, containing script code will be executed in the web 
browsers environment of the user:
http://192.168.168.168/<script>alert("XSS")</script>

If an attacker supplies a username, via the uName parameter, containing 
script code at the login-page of the device, an entry in the system log 
file will be inserted containing the tainted "username".

As the system log file is displayed in HTML format, the administrator 
viewing the log file will execute the injected script code.

As the length of the input field is limited by the browser (client side), 
you can insert the following short script into the username field to do a 
quick verification of this vulnerability:
</TD><script>alert("!")</script>


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> Oliver 
Karow.



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.