SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

BlueSocket web administration is vulnerable to XSS


Arrow  SecurityAlert : 1991
Arrow  CVE : CVE-2006-6363
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : Yes
Arrow  Credit : ISecAuditors
Arrow  Published : 08.12.2006

Arrow  Affected Software : BlueSocket



Arrow  Advisory Content :  

=============================================
INTERNET SECURITY AUDITORS ALERT 2006-007
- Original release date: April 27, 2006
- Last revised: December 1, 2006
- Discovered by: Jesus Olmos Gonzalez
- Severity: 2/5
=============================================

I. VULNERABILITY
-------------------------
The BlueSocket web administration is vulnerable to a Cross Site
Scripting attack.

II. BACKGROUND
-------------------------
BSC 2100 product is included in the Blue Secure Family
(www.bluesocket.com)

BlueSecure Controllers provide high-performance, reliable,
policy-based WLAN security and management solutions that have been
deployed by hundreds of large institutions, enterprises, and public
access providers.

III. DESCRIPTION
-------------------------
The admin.pl perl code don't sanitize the imputs and then wen it tries
to rewrite the username at the input, html + script code could be
rewrited and executed by the browser.

This crossite is in the administration of the security product, it has
been tested only in BSC 2100.

Is it possible to send a fake email to the admin spoofing the product
address, saying that the configuration is not ok and sending the
special link.

If the admin press the link and validate in aparently normal
interface, his credentials will be sended to the attacker.

If this is done with a good social engineering will be a great risk.

IV. PROOF OF CONCEPT
-------------------------
This POC will inject some html to modify the look and feel of the
authentication, and attacker could inject script code to send
credentials to him.

https://somehost.somedomain.org/admin.pl?ad_name=%22%3E%3Ch1%3EXSS%20BUG
%3C/h1%3E%3C!--

V. BUSINESS IMPACT
-------------------------
Credentials could be stolen due social engineering attacks.

VI. SYSTEMS AFFECTED
-------------------------
Versions prior 5.2 or without 5.1.1-BluePatch

VII. SOLUTION
-------------------------
Update to 5.2 version or apply 5.1.1-BluePatch

VIII. REFERENCES
-------------------------
Vulnerability item number 4484 in the Bluepatch V6 for 5.1.1.1 Release
Notes.

IX. CREDITS
-------------------------
This vulnerability has been discovered and reported by
Jesus Olmos Gonzalez (jolmos (at) isecauditors (dot) com).

X. REVISION HISTORY
-------------------------
April 27, 2006: Initial vendor contact.
April 28, 2006: Vendor updates its near patch.
June 21, 2006: Publication of the patch.
September 16, 2006: Vendor confirms inclusion in referenced patch.
September 17, 2006: Advisory revised.

XI. DISCLOSURE TIMELINE
-------------------------
April 26, 2006: The vulnerability discovered by
Internet Security Auditors.
December 1, 2006: Advisory finally Published

XII. LEGAL NOTICES
-------------------------
The information contained within this advisory is supplied "as-is"
with no warranties or guarantees of fitness of use or otherwise.
Internet Security Auditors, S.L. accepts no responsibility for any
damage caused by the use or misuse of this information.





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

» PHP 5.3.0 5.2.11
   posix_mkfifo()
   open_basedir bypass

Copyright © SecurityReason.com. All Rights Reserved.