SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow World Laboratory of Bugtraq Database

Arrow  Topic :

Portwise SSL VPN 4.6 cross site scripting


Arrow  WLB : WLB-2010020110  (About)
Arrow  SecurityAlert : 7050
Arrow  Date : 2010-02-20
Arrow  Credit          : null
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote : Yes
Arrow  Local     : No
Arrow  Status   : Bug

Arrow  History : [2010-02-20] Started

Arrow  Affected software :  Portwise SSL VPN 4.6



Arrow  Text :  

PR09-04: Cross-Site Scriting on Portwise SSL VPN v4.6

Vulnerability found: 25th March 2009

Vendor informed: 28th April 2009

Vulnerability fixed:

Severity: Medium

Description:

The Portwise portal login page is vulnerable to XSS. Portwise is a
SSL-VPN portal.

Note: Other version might be affected as well

The following demonstrate XSS:

1) Login page XSS

https://example.com/wa/auth?&authmech=Assess&reloadFrame=%22;%3Cscr
ipt%3
Eblah%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

Consequences:

An attacker may be able to cause execution of malicious scripting code
in the browser of a user who clicks on a link to a Portwise Portal-based
site. Such

code would run within the security context of the target domain. This
type of attack can result in non-persistent defacement of the target
site, or the

redirection of confidential information (i.e.: session IDs) to
unauthorised third parties.

Fix:

Ensure all input parameters (especially "reloadFrame") are
filtered
sufficiently before beign echoed back to the client.

References:

http://www.procheckup.com/Vulnerabilities.php

Credits: George Christopoulos and Jan Fry of ProCheckUp Ltd
(www.procheckup.com)

Legal:

Copyright 2009 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the

Bulletin is not edited or changed in any way, is attributed to
Procheckup, and provided such reproduction and/or distribution is
performed for non-

commercial purposes.

Any other use of this information is prohibited. Procheckup is not
liable for any misuse of this information by any third party.



Audyt bezpieczeństwa

Security Audit

Analiza powłamaniowa

Arrow  References :  

None

If you want change this note, please use UCP



Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

Copyright © SecurityReason.com. All Rights Reserved.