The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


[SCSA-001] Sambar Server Cross-Site Scripting vulnerability


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 22 Jan 2003 21:58:36 -0000
From: "Le Bras "GrИgory" <[email protected]>
To: [email protected]
Subject: [SCSA-001] Sambar Server Cross-Site Scripting vulnerability



.: Sambar Server Cross-Site Scripting vulnerability :.
________________________________________________________________________

Security Corporation Security Advisory [SCSA-001]
________________________________________________________________________

PROGRAM: Sambar Server
HOMEPAGE: http://www.sambar.com/
VULNERABLE VERSIONS: 5.3 and prior
________________________________________________________________________


DESCRIPTION
________________________________________________________________________

"Sambar Server is the new standard in high performance multi-functional
servers with features rivaling other commercial products selling
separately for several hundreds of dollars. It's Winsock2 compliant Win32
 integration functions on Windows 95, Windows 98, Windows NT, Win2000,
and XP as a service or as an application."
(direct quote from http://sambar.jalyn.net)


DETAILS
________________________________________________________________________


An exploitable bug was found on Sambar Server which cause javascript
execution on client's computer by following a crafted url.

This kind of attack known as "Cross-Site Scripting Vulnerability" is
present in search section of the web site, anyone can input specially
crafted links and/or other malicious scripts.


EXPLOITS
________________________________________________________________________


http://localhost/search/results.stm?query=<;script>alert('Test%20of%
20vulnera
bility');&lt;/script&gt;


SOLUTIONS
________________________________________________________________________

"Until a patch is available, this vulnerability can only be eliminated by 
removing the search/results.stm search page and thereby disabling search"


VENDOR STATUS
________________________________________________________________________

Sambar has been contacted. (http://www.sambar.com/security.htm)
No update available for the moment.


------------------------------------------------------------------
GrИgory Le Bras aka GaLiaRePt | http://www.Security-Corp.org
------------------------------------------------------------------

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру