[UNIX] Cobalt RaQ Cross Site Scripting, Directory Traversal and DoS Vulnerabilities

Date: 03/02/02

  Cobalt RaQ Cross Site Scripting, Directory Traversal and DoS


The Sun Cobalt RaQ is a server appliance for Internet Service Providers
(ISPs). It can host up to 200 individual websites or it can be dedicated
to a single medium or large customer.
Multiple security vulnerabilities have been found in the product, and
though the vulnerabilities require a valid account on the Cobalt machine,
they are dangerous nonetheless.


Cross site scripting:
Cobalt's service.cgi incorrectly handles the incoming search parses,
incoming HTML tags or JavaScript will be included inside the result
without them being filtered out for dangerous content.

Affected CGIs:

1) Delete service.cgi from the system, or disable it from execution.
2) Delete alert.cgi from the system, or disable it from execution




Tag images:>

Write document:>document.write(document.domain)</SCRIPT>

Directory traversal:
A directory traversal vulnerability exists by default in the CGI:
"/usr/admserv/html/.cobalt/admin". The CGI would allow you to access any
restricted files.


# Access file for /usr/admserv/html/.cobalt/admin/ (admin )
order allow,deny
allow from all
require user admin
Authname CobaltRaQ
Authtype Basic

Denial of service:
The server crashes when it receives a very long URL.



The information has been provided by <mailto:al3xhernandez@ureach.com>
Alex Hernandez.


