OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA11479] Network Query Tool Cross Site Scripting Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Mon Apr 26 2004 - 08:25:25 CDT


TITLE:
Network Query Tool Cross Site Scripting Vulnerability

SECUNIA ADVISORY ID:
SA11479

VERIFY ADVISORY:
http://secunia.com/advisories/11479/

CRITICAL:
Less critical

IMPACT:
Cross Site Scripting, Exposure of sensitive information

WHERE:
From remote

SOFTWARE:
Network Query Tool 1.x

DESCRIPTION:
Janek Vind has reported a vulnerability in Network Query Tool,
allowing malicious people to conduct Cross Site Scripting attacks.

1) If error messages hasn't been turned off in PHP, the "nqt.php"
script will return error messages if an invalid value is supplied to
the "portNum" parameter. This can be exploited to reveal the
installation path.

2) Input passed to the "portNum" parameter in the "nqt.php" script
isn't properly verified before it is returned to the user. This can
be exploited to execute arbitrary HTML or script code in a user's
browser session in context of an affected site by tricking the user
into visiting a malicious website or follow a specially crafted
link.

The vulnerabilities have been reported in version 1.6. Prior versions
may also be affected.

SOLUTION:
Edit the source code to ensure that input is properly sanitised.

PROVIDED AND/OR DISCOVERED BY:
Janek Vind "waraxe"

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------