exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Snare For Linux Cross Site Scripting

Snare For Linux Cross Site Scripting
Posted Dec 10, 2012
Authored by Andrew Brooks

Snare for Linux suffers from a cross site scripting vulnerability via log injection. All versions prior to 1.7.0 are vulnerable.

tags | exploit, xss
systems | linux
advisories | CVE-2011-5249
SHA-256 | d22ada759dcbc1d17dafab44a19f943b1bb0c438c37fb13503433ad75f387109

Snare For Linux Cross Site Scripting

Change Mirror Download
Snare for Linux Cross-Site Scripting via Log Injection


I. BACKGROUND
----------------------
Snare for Linux provides a 'C2' or 'CAPP' style audit
subsystem for the Linux operating system. It can be
used as a standalone auditing tool for Linux, or can
send data to the Snare Server for analysis and storage.


II. DESCRIPTION
----------------------
A cross-site scripting vulnerability has been discovered
in the web interface for Snare for Linux. As part of
Snare's intended functionality, one feature it provides
is the logging of shell commands issued by a given user
which are then available for viewing through the web
interface. Due to the fact that this data was not validated
before being sent to the browser in versions prior to 1.7.0,
it is possible to inject JavaScript into the web console.


III. AFFECTED PRODUCTS
----------------------
All versions of Snare for Linux prior to 1.7.0 are vulnerable.


IV.
----------------------
Users should upgrade to version 1.7.0 of Snare for Linux.


V. Credit
----------------------
This vulnerability was discovered by Andrew Brooks.


VI. References
----------------------
CVE-2011-5249
http://rpmfind.net/linux/RPM/sourceforge/s/sn/snare/Snare%20for%20Linux/1.7.0/SnareLinux-1.7.0-0.i386.html


VII. Timeline
----------------------
7/11/11 - Vendor notification
8/09/11 - Fixed and closed
Login or Register to add favorites

File Archive:

June 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    18 Files
  • 2
    Jun 2nd
    13 Files
  • 3
    Jun 3rd
    0 Files
  • 4
    Jun 4th
    0 Files
  • 5
    Jun 5th
    32 Files
  • 6
    Jun 6th
    39 Files
  • 7
    Jun 7th
    22 Files
  • 8
    Jun 8th
    17 Files
  • 9
    Jun 9th
    20 Files
  • 10
    Jun 10th
    0 Files
  • 11
    Jun 11th
    0 Files
  • 12
    Jun 12th
    0 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close