SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#114070

NetScreen Instant Virtual Extranet (IVE) platform contains cross-site scripting vulnerability in delhomepage.cgi

Overview

NetScreen Instant Virtual Extranet (IVE) platform contains a cross-site scripting vulnerability in the row parameter of delhomepage.cgi, which could allow an attacker to mount a cross-site scripting attack.

I. Description

The Instant Virtual Extranet platform is an application security gateway that includes a built-in web server. The delhomepage.cgi script does not adequately validate the value of the row parameter. It is possible to use a cross-site scripting technique to inject malicious script (JavaScript, VBScript, etc.) or HTML into a web page using a specially crafted row parameter.

According to NetScreen:

    The scope of the problem is limited because only authenticated users can access the affected URL.

II. Impact

A remote attacker could access sensitive information related to the vulnerable web page (cookies, form values, URI data). The attacker could also attempt to mislead the user into providing sensitive information such as login credentials.

III. Solution

Apply Patch

NetScreen has provided a patch to address this vulnerability. For details on obtaining the patch corresponding to your currently installed release, please refer to the NetScreen Advisory.

Systems Affected

VendorStatusDate NotifiedDate Updated
NetScreenVulnerable9-Mar-2004

References

http://www.netscreen.com/services/security/alerts/ive_xss.txt
http://secunia.com/advisories/11025/
http://www.cert.org/archive/pdf/cross_site_scripting.pdf
http://www.neoteris.com/products/functoverview.html

Credit

This vulnerability was reported by Mark Lachniet.

This document was written by Damon Morda.

Other Information

Date Public:2004-03-02
Date First Published:2004-03-09
Date Last Updated:2004-03-09
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Severity Metric:1.03
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader