J-Security Center

Title: ht://Check Web Header Script Injection Vulnerability

Severity: HIGH

Description:

ht://Check is a link checker based upon ht://Dig. It is capable of retrieving information through HTTP/1.1 and storing the results in a MySQL database so that it can return information on broken links, page not found messages, content-type, and HTTP status code summaries.

ht://Check does not properly sanitize the information it retrieves and stores in the MySQL database after performing a web crawl. HTML tags may be included in the crawled webservers' Server: headers and other information.

Script code contained in the HTML could be executed in the security context of the vulnerable webserver. Successful exploitation of this vulnerability could enable an attacker to execute code in the security context of a trusted site. This vulnerability may be exploited to steal cookie-based authentication credentials from legitimate users.

Affected Products:

  • Debian Linux 3.0.0
  • Debian Linux 3.0.0 alpha
  • Debian Linux 3.0.0 arm
  • Debian Linux 3.0.0 hppa
  • Debian Linux 3.0.0 ia-32
  • Debian Linux 3.0.0 ia-64
  • Debian Linux 3.0.0 m68k
  • Debian Linux 3.0.0 mips
  • Debian Linux 3.0.0 mipsel
  • Debian Linux 3.0.0 ppc
  • Debian Linux 3.0.0 s/390
  • Debian Linux 3.0.0 sparc
  • Gabriele Bartolini ht://Check 1.1.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.