|
|
[ Message Precedent sur la mailing][ Message Suivant sur la mailing][ Precedent dans le fil][ Prochain dans le fil][ Index par Date][ Index par fil]
Praetorian Advisory: Reflective XSS in Alkaline Search Engine Server
Advisory Title: Reflective XSS in Alkaline Search Engine Server
Release Date: 02-10-2010
Vendor: Vestris, Inc.
Application: Alkaline Search Engine Server
Version: 1.9
Overview:
Alkaline is a multi-platform, all-in-one index and search engine server.
Details:
The web interface for the Alkaline Search Engine Server does not
validate user input or sanitize its output prior to display in the
viewing page. Subsequently, a malicious user can use the Alkaline
server to perform unauthenticated, reflective cross-site scripting
attacks by passing arbitrary scripting content in the request which
the server will display verbatim in the error message it returns.
Example:
link://[click]<9999>/<script>alert('test');</script>/a
Vendor Response:
The vendor, Vestris Inc, has been contacted on the matter and stated
both the software and the company are no longer in operation. Alkaline
version 1.9 is the last release of the product and no patches will be
made available for this or any other vulnerability. According to the
company's website "Vestris is gone, but we're giving it all away for
free. You can download software from this page..."
Although the product has reached end of life, the software is still
available for download and has been identified in DMZ environments.
For these reasons, value is still seen in disclosure.
Recommendation:
Given the state of the software, end users should ascertain whether
instances identified in their environment still have a legitimate
purpose and discontinue servers appropriately. Cursory review suggests
several other vulnerabilities are present in the product, but an
in-depth analysis has not been performed.
For more information please visit link://[click] or
email research@xxxxxxxxxxxxxxxxx
Praetorian General PGP Key:
link://[click]
This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!
link://[click]
--------------------------------------
Archives de la liste de diffusion Secunia
Archives de la liste de diffusion BugTraq
Archives de la liste de diffusion DailyDave
Archives de la liste de diffusion FunSec
Archives de la liste de diffusion Full Disclosure
Archives de la liste de diffusion Focus-IDS (FD)
Archives de la liste de diffusion Webappsec (FD)
Archives de la liste de diffusion Security-basics (FD)
Archives de la liste de diffusion Vulndiscuss
Archives de la liste de diffusion Vulnwatch
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, microsoft, attaque, réseau, outil, vulnérabilité, audit, système, virus, internet, données, metasploit, présentation, linux, bluetooth, protocol, source, vista, scanner, réseaux, shell, rootkit, engineering, conférence, trames, paquet, téléphone, wishmaster, sysun, noyau, mobile, libre, botnet, https, téléphones, rapport, mémoire, scapy, google, patch, reverse, navigateur, snort |
| Mini-Tagwall de l'annuaire video : | | | | security, vmware, virus, biometric, metasploit, windows, lockpicking, password, botnet, tutorial, attack, network, linux, exploit, crypt, source, iphone, secconf, server, shmoocon, conficker, engineering, virtual, wimax, ettercap, rootkit, wireshark, reverse, hackitoergosum, cisco, internet, systm, hacker, firewall, wireless, openbsd, meterpreter, openssh, access, conference, knoppix, arduino, backtrack, brucon, remote |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|