[UNIX] Critical Path inJoin Directory Server Cross Site Scripting Issue
From: support@securiteam.comDate: 05/12/02
- Previous message: support@securiteam.com: "[UNIX] Unfortunate Interaction Between EZMLM and MessageLabs Virus Scanning"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Sun, 12 May 2002 14:48:49 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Critical Path inJoin Directory Server Cross Site Scripting Issue
------------------------------------------------------------------------
SUMMARY
This advisory documents cross-site scripting vulnerabilities in the
Web-based administrator interface, named iCon, of the inJoin Directory
Server that allows an attacker with the correct username and password to
inject HTML script and use the server in a cross-site scripting attack.
DETAILS
Vulnerable systems:
* Critical Path inJoin version 4.0 Directory Server
Immune systems:
* Critical Path inJoin version 4.1.4.7 Directory Server
The administrative web server, iCon, listens on TCP port 1500, and runs
under the ids account. By connecting to this port using a web browser and
entering a correct administrator username and password, an operator can
remotely administer the Directory Server. Testing of various
administrative URL's located situations in which script can be injected
and executed upon rendering of the response. Two examples are as follows,
http://ip:1500/DSASD&DSA=1&LOCID=