Vissza a www.andrews.hu-ra

    [guru] [dbounds@gmail.com: Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability]


    DATE: Thu, 03 Aug 2006 13:48:10 +0200
    A Juniper Networks DX Web gyorító adminisztrációs felülete XSS hibát
    tartalmaz, a támadó adminisztrátori jogokat szerezhet.
    
    
    ----- Forwarded message from Darren Bounds <dbounds@gmail.com> -----
    
    Date: Mon, 10 Jul 2006 12:16:09 -0400
    From: "Darren Bounds" <dbounds@gmail.com>
    To: full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com
    Subject: Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability
    
    Juniper Networks DX Web Administration Persistent System Log  XSS 
    Vulnerability
    July 10, 2006
    
    Product Overview:
    The Juniper Networks (Redline) DX application acceleration platform
    delivers a complete data center acceleration solution for web-enabled
    and IP-based business applications.
    
    Vulnerability Details:
    The Juniper Networks DX System log is vulnerable to a persistent,
    unauthenticated XSS attack. This vulnerability can be exploited by an
    attacker to obtain full administrative access to the Juniper DX appliance.
    
    This vulnerability stems from failure to sanitize System log content
    within the web administration interface. A malicious user may insert
    content into the username login field which will then be executed by
    administrative users when viewing the System Log.
    
    Affected Versions:
    Juniper DX 5.1.x
    Olders versions may also be affected.
    
    Workarounds:
    Control network access to the DX web administration console.
    
    References:
    http://www.juniper.net/products/appaccel/dca/dx.html
    
    
    ----- End forwarded message -----
    
    
    

    Vissza a www.andrews.hu-ra