Symantec Gateway Security Management Service Cross Site Scripting
Brian_J_Soby_at_raytheon.com
Date: 02/27/04
- Previous message: Ollivier Robert: "Re: Calife heap corrupt / potential local root exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: bugtraq@securityfocus.com Date: Fri, 27 Feb 2004 11:12:53 -0500
Symantec Gateway Security Management Service Cross Site Scripting
Product: Symantec Gateway Security 2.0
Date: 02/25/2004
Author: Brian Soby, Raytheon
1. Overview
----------------------------------------
A cross site scripting vulnerability exists in Symantec Gateway Security's
management service which could allow an attacker to hijack a management
session to the device.
2. Vulnerability Description
----------------------------------------
A vulnerability exists in the Symantec Gateway Security management server
object's handling of URLs when including them in error pages displayed to
the requesting client. No parsing is done to the URLs to ensure that HTML
tags are not included and returned to the client.
3. Conditions
---------------------------------------
The URL requested by the client must be handled by the Symantec Gateway
Security's custom server object. For example, any request for an object
under the /sgmi directory is passed to the Symantec Gateway Security
server object for processing. The attacker could present a URL in the form
of https://FirewallHostname:2456/sgmi/