full-disclosure-uk May 2008 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: [Full-disclosure] SonicWall e-mail security

[Full-disclosure] SonicWall e-mail security Host Header XSS Vulnerability

From: Deniz Cevik <Deniz.Cevik_at_nospam>
Date: Thu May 08 2008 - 15:04:54 GMT
To: <full-disclosure@lists.grok.org.uk>, <bugtraq@securityfocus.com>


Affected Software/Device: SonicWall E-mail Security  

Version: 6.1.1  

Vulnerability: Cross Site Scripting  

Risk: Low  

Description: SonicWALL Email Security is award-winning anti-spam, anti-virus, anti-phishing, policy, and compliance management e-mail protection solution. Available as a hardened appliance or as Windows software, SonicWALL Email Security protects inbound and outbound e-mail for organizations of less than 25 to over 100,000 users.  

Sonicwall web application utilizes host header for serving 404 Error pages. The vulnerability can be exploited by requesting a non-existing web page with a specially crafted host header. As the application does not properly sanitize the data contained in the host header, desired script code can be run on client browser.    

Sample Request:  

GET /blah.htm HTTP/1.1

Host: "><script>alert('XSS');</script>  

Deniz CEVIK

www.intellectpro.com.tr



Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/