HTTP: HTML Script Tag Embedded in User-Agent

This signature detects cross site scripting attacks. Attackers can create a malicious Web site that includes HTML embedded in the hyperlinks, which might violate site security settings. Attackers can then view the Web cookies from a target computer. Web cookies typically contain sensitive information such as usernames, passwords, credit card numbers, social security numbers, and bank account numbers.

Extended Description

raSMP is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

Affected Products

Rasmp rasmp

Short Name
HTTP:XSS:HTML-SCRIPT-IN-UA
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2006-0084 CVE-2014-2647 CVE-2014-8469 CVE-2023-0992 Embedded HTML Script Tag User-Agent bid:16138 bid:71180 in
Release Date
03/20/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3631
False Positive
Unknown
Vendors

Rasmp

CVSS Score

5.0

4.3

Found a potential security threat?