| VID |
22289 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The Icecast program, according to its version number, has a 'list.cgi' Cross-Site Scripting Vulnerability. Icecast is an open-source mp3 broadcasting program for Windows and Unix-based operating systems. Some Icecast versions are vulnerable to a cross-site scripting vulnerability in the status display functionality, caused by a failure of the application to properly sanitize user-supplied input. A remote attacker could create a malicious URL link to the 'list.cgi' script containing embedded JavaScript in the UserAgent variable and then persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
* Note: This check solely relied on the version number of the remote Icecast to assess this vulnerability, so this might be a false positive.
* References: http://securitytracker.com/alerts/2004/Aug/1011046.html
* Platforms Affected: Icecast Any version Debian Project, Debian Linux 3.0 |
| Recommendation |
For Debian GNU/Linux 3.0: Upgrade to the latest version of icecast-server (1.3.11-4.2 or later), as listed in Debian Security Advisory DSA-541-1 at http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1020.html |
| Related URL |
CVE-2004-0781 (CVE) |
| Related URL |
11021 (SecurityFocus) |
| Related URL |
17086 (ISS) |
|