Skip to main content

Tags Cross-Site Scripting

VoIPmonitor: cross-site scripting via SIP messages

Description

Multiple Cross-Site Scripting vulnerabilities were observed in the VoIPmonitor WEB GUI. These vulnerabilities can be exploited by sending SIP messages towards hosts monitored by VoIPmonitor. During our tests, the following areas were affected:

Read more about VoIPmonitor: cross-site scripting via SIP messages

Juniper VPN SSL: client-side cross-site scripting

Description

The Juniper VPN SSL system was found to be vulnerable to a client-side cross site scripting vulnerability.

Impact

Exploitation of this vulnerability may allow hijack of VPN SSL sessions. This usually involves a social engineering attack in order to convince a logged in victim to click on an attacker-supplied URL. Therefore such an attack would typically be the result of a targeted attack rather than an opportunistic one.

Read more about Juniper VPN SSL: client-side cross-site scripting

Applicure dotDefender: stored cross-site scripting in admin interface

Published on Jun 1, 2010 in , ,

An advisory by EnableSecurity.

Description

Applicure dotDefender is a Web Application Firewall that can be installed on Windows and Linux servers.

From their website (applicure.com):

“dotDefender is the market-leading software Web Application Firewall (WAF). dotDefender boasts enterprise-class security, advanced integration capabilities, easy maintenance and low total cost of ownership (TCO). dotDefender is the perfect choice for protecting your website and web applications today.”

Read more about Applicure dotDefender: stored cross-site scripting in admin interface

Armorlogic Profense WAF: multiple vulnerabilities

An advisory by EnableSecurity. Trustwave published a joint advisory named TWSL2009-001.

Description

Armorlogic Profense is a Web Application Firewall and load balancing solution.

From their website (armorlogic.com):

“Protecting and securing websites and web applications can be a complicated business. Profense web application firewall simplifies protection with an affordable and easy to use, feature rich, solution that gives you full PCI DSS 1.1 and 1.2 section 6.6 compliance.”

Read more about Armorlogic Profense WAF: multiple vulnerabilities

OpenX: multiple vulnerabilities

An advisory by EnableSecurity in collaboration with Acunetix.

Description

OpenX is an online advertising web application written in PHP that supports popular sites such as TechCrunch, SUN Microsystems and Metacafe.

From their website (openx.org):

“OpenX is a free, open source ad server that manages the selling and delivery of your online advertising inventory. You can get OpenX as a hosted service or as downloaded software.”

Read more about OpenX: multiple vulnerabilities