Secunia SmallBusiness
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA49334

Bloxx Web Filtering Multiple Vulnerabilities
Secunia Advisory SA49334
Secunia VIM 4.0 - Free Trial
Release Date 2012-06-04
Last Update 2012-06-21
   
Popularity 896 views
Comments 0 comments

Criticality level Moderately criticalModerately critical
Impact Security Bypass
Cross Site Scripting
Where From remote
Authentication level This information is available to Secunia VIM customers
   
Report reliability This information is available to Secunia VIM customers
Solution Status Vendor Patch
   
Systems affected This information is available to Secunia VIM customers
Approve distribution This information is available to Secunia VIM customers
Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI
   
Operating System
Bloxx Web Filtering 5.x

Secunia CVSS Score This information is available to Secunia VIM Customers
CVE Reference(s) CVE-2012-2563 CVSS score available to Secunia VIM customers
CVE-2012-2564 CVSS score available to Secunia VIM customers
CVE-2012-2565 CVSS score available to Secunia VIM customers
CVE-2012-2566 CVSS score available to Secunia VIM customers
CVE-2012-3343 CVSS score available to Secunia VIM customers
  

Description

Multiple vulnerabilities have been reported in Bloxx Web Filtering, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to bypass certain security restrictions and conduct cross-site scripting, cross-site request forgery, and script insertion attacks.

1) Input passed via the URL is not properly sanitised before being used to construct reports from filtered web content. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is viewed.

2) Input passed via the "Full Name" field to Administrators of the Administrators section, via the Name and Description fields to Categories of the "Filtering & Protection" section, via the Name field to Identify of the Identification section, via the Username field to Users of the "Users & Groups" section, via the Name and Description fields to Groups of the "Users & Groups" section, via Name and Description fields to "Filtering Policies", via the "Original URL" and Redirection fields to "Proxy & Cache", via the Destination field to Email of the Alerts section, via the Name field to "Access Denied Page" of the "Appliance Customization" section, via the Name field to "Login Page" of the "Appliance Customization" section, via the Name field to "Logout Denied Page" of the "Appliance Customization" section is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site if malicious data is viewed.

3) The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to cause unspecified impacts by tricking a logged in administrator into visiting a malicious web site.

4) Input passed via the URL when using HTTPS is not properly sanitised before being returned to the user in a Microdasys SSL error page. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Successful exploitation requires that the target server of the URL does not support HTTPS.

5) An error due to the application not properly verifying the X-Forwarded-For HTTP header can be exploited to bypass IP restrictions and access blocked sites.

The vulnerabilities are reported in versions prior to 5.0.14.


Solution
Update to version 5.0.14.

Provided and/or discovered by
US-CERT credits Travis Lee.

Changelog
Further details available to Secunia VIM customers

Original Advisory
US-CERT:
http://www.kb.cert.org/vuls/id/722963

Other references
Further details available to Secunia VIM customers

Deep Links
Links available to Secunia VIM customers


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: Bloxx Web Filtering Multiple Vulnerabilities
 
No posts yet

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2013 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability