Summary
This host is installed with InterWorx Web
Control Panel and is prone to information disclosure and xss vulnerability.
Impact
Successful exploitation will allow attacker
to execute arbitrary HTML and script code and disclose certain sensitive information in the context of an affected site.
Impact Level: Application
Solution
Update to version 5.0.13 build 574 or later,
For updates refer http://www.interworx.com
Insight
Flaw is due to improper sanitization of
user-supplied input passed via 'i' parameter to xhr.php and certain unspecified input passed to the SiteWorx interface.
Affected
InterWorx version 5.0.12 build 569,
Other versions may also be affected.
Detection
Send a crafted request via HTTP GET and
check whether it is able to read cookie or not.
References
Severity
Classification
-
CVE CVE-2014-2035 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- aeNovo Database Content Disclosure Vulnerability
- Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
- Apache Tomcat Information Disclosure Vulnerability
- Apache Rave User Information Disclosure Vulnerability
- Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities