| VID |
21614 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Sambar Web server is vulnerable to multiple cross site scripting attacks in the administrative interface. Sambar Server is a multi-threaded HTTP server with integrated FTP, Mail, and Proxy server services. Sambar Server versions 6.2 and earlier are vulnerable to a cross-site scripting vulnerability, caused by improper validation of user-supplied input passed to the "indexname" parameter in "search/results.stm" and the "RCredirect" parameter in "session/logout" of the administrative interface. This vulnerability could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
* References: http://www.sambar.com/security.htm http://secunia.com/advisories/15465/
* Platforms Affected: Sambar Server versions 6.2 and earlier Microsoft Windows Any version Red Hat Linux 8.0 |
| Recommendation |
Update to the latest version of Sambar Server (6.2.1 or later), available from the Sambar Technologies Web site at http://www.sambar.com |
| Related URL |
(CVE) |
| Related URL |
13722 (SecurityFocus) |
| Related URL |
20710 (ISS) |
|