Otkrivena je ranjivost u operacijskom sustavu HP webOS koja zlonamjernim napadačima omogućuje izvršavanje XSS napada.
Paket:
HP webOS 3.x
Operacijski sustavi:
HP webOS 3.x
Problem:
neodgovarajuća provjera ulaznih podataka
Iskorištavanje:
udaljeno
Posljedica:
umetanje HTML i skriptnog koda
Rješenje:
zaobilazno rješenje (workaround)
Izvorni ID preporuke:
SA45126
Izvor:
Secunia
Problem:
Ranjivost je vezana uz neadekvatnu provjeru ulaznih podataka o imenu i prezimenu kontakata u aplikaciji za upravljanje kontaktima prije njihovog prikaza korisniku.
Posljedica:
Otkrivena ranjivost može se iskoristiti za izvršavanje proizvoljnog HTML i/ili skriptnog koda u kontekstu napadnutog uređaja.
Rješenje:
Korisnicima se savjetuje da ne prihvaćaju zapise o kontaktima dobivene od nepouzdanih izvora te da instaliraju novu inačicu čim se objavi.
HP webOS Contacts Application Cross-Site Scripting Vulnerability
Secunia Advisory SA45126
Release Date 2011-07-07
Criticality level Less criticalLess critical
Impact Cross Site Scripting
Where From remote
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Unpatched
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia VIM
Operating System
HP webOS 3.x
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A vulnerability has been reported in HP webOS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Input passed to the first name and last name in the contacts application is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in context of an affected device.
The vulnerability is reported in version 3.0. Other versions may also be affected.
Solution
Do not accept contact records from untrusted sources. Apply the next over-the-air update when it becomes available.
Provided and/or discovered by
malloc(i)
Original Advisory
http://cybermediaplanet.com/security/webOS3.0/webOS3.0%20-%20PoC.txt
Posljednje sigurnosne preporuke