ZyWALL Input Validation Hole Permits Cross-Site Scripting Attacks
|
|
SecurityTracker Alert ID: 1020000
|
|
SecurityTracker URL: http://securitytracker.com/id?1020000
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: May 9 2008
|
Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information
|
Exploit Included: Yes
|
Version(s): ZYWall 100
|
Description: A vulnerability was reported in ZyWALL. A remote user can conduct cross-site scripting attacks.
The device does not properly filter HTML code from user-supplied input in the HTTP Referer header parameter before displaying the
input. A remote user can create a specially crafted request that, when loaded by a target user, will cause arbitrary scripting
code to be executed by the target user's browser. The code will originate from the site running the ZyWALL software and will run
in the security context of that site. As a result, the code will be able to access the target user's cookies (including authentication
cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take
actions on the site acting as the target user.
Deniz Cevik reported this vulnerability.
|
Impact: A remote user can access the target user's cookies (including authentication cookies), if any, associated with the site running the
ZyWALL software, access data recently submitted by the target user via web form to the site, or take actions on the site acting
as the target user.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.zyxel.com/ (Links to External Site)
|
Cause: Input validation error
|
Reported By: "Deniz Cevik" <Deniz.Cevik@intellect.com.tr>
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 8 May 2008 18:12:45 +0300
From: "Deniz Cevik" <Deniz.Cevik@intellect.com.tr>
Subject: ZYWALL Referer Header XSS Vulnerability
|
Affected Software/Device: Zyxel ZYWall 100
Vulnerability: Cross Site Scripting
Risk: Low
Description: The ZyWALL 100 is designed to act as a secure gateway via
xDSL/Cable modems or broadband routers for small to medium size
companies. The ZyWALL 100 features an ICSA certified firewall, IPSec VPN
capability, MultiNAT, web pages content filtering and an embedded web
configurator for easy configuration and management.
ZyWALL web based management interface utilizes referer header for
serving 404 Error pages. The vulnerability can be exploited by
requesting a non-existing web page with a specially crafted referer
header. As the application does not properly sanitize the data contained
in the referer header, desired script code can be run on client browser.
Sample Request:
GET /blah.htm HTTP/1.1
Host: www.site.com
Referer: blaaaa"><script>alert(12345)</script>aaaah.htm
Deniz CEVIK
www.intellectpro.com.tr
|
|