FreeBSD : Pubcookie Login Server -- XSS vulnerability (115a1389-858e-11e0-a76c-000743057ca2)

high Nessus Plugin ID 54619

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Nathan Dors, Pubcookie Project reports :

A new non-persistent XSS vulnerability was found in the Pubcookie login server's compiled binary 'index.cgi' CGI program. The CGI program mishandles untrusted data when printing responses to the browser. This makes the program vulnerable to carefully crafted requests containing script or HTML. If an attacker can lure an unsuspecting user to visit carefully staged content, the attacker can use it to redirect the user to his or her local Pubcookie login page and attempt to exploit the XSS vulnerability.

Solution

Update the affected package.

See Also

http://www.pubcookie.org/news/20070606-login-secadv.html

http://www.nessus.org/u?33fbf6f2

Plugin Details

Severity: High

ID: 54619

File Name: freebsd_pkg_115a1389858e11e0a76c000743057ca2.nasl

Version: 1.9

Type: local

Published: 5/24/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:pubcookie-login-server, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 5/23/2011

Vulnerability Publication Date: 5/25/2007