CVE-2008-4918
SonicWALL Content-Filtering Universal Script Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en SonicWALL SonicOS Enhanced anterior a v4.0.1.1, como el utilizado en SonicWALL Pro 2040 y TZ 180 y 190; permite a atacantes remotos inyectar secuencias de comandos Web o HTML en sitios web de su elección a través de una URL a un sitio que se basa en el bloqueo de filtrado de contenidos; esto no se maneja adecuadamente en la página de bloqueo CFS. También se conoce como "secuestro universal del sitio web" (universal website hijacking).
This vulnerability allows remote attackers to execute a script injection attack on arbitrary sites through vulnerable installations of SonicWALL. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page or open a malicious web link.
The specific flaw exists in the default error page displayed when a user requests access to a web site that is blocked based on the devices content-filtering rules. Insufficient sanity checks allow an attacker to craft a URL that will trigger an error and simultaneously inject a malicious script. As the browser is unable to differentiate between content delivered from the original top level site requested and the inline device, the script injection occurs under the context of the target domain. This can result in various further compromise.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-10-30 CVE Published
- 2008-10-30 First Exploit
- 2008-11-04 CVE Reserved
- 2024-07-26 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/32498 | Not Applicable | |
http://securityreason.com/securityalert/4556 | Third Party Advisory | |
http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking | Third Party Advisory | |
http://www.securityfocus.com/archive/1/497948/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/497958/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/497968/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/497989/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/498043/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/498073/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/31998 | Third Party Advisory | |
http://www.sonicwall.com/downloads/SonicOS_Enhanced_4.0.1.1_Release_Notes.pdf | Broken Link | |
http://www.zerodayinitiative.com/advisories/ZDI-08-070 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46232 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32552 | 2008-10-30 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sonicwall Search vendor "Sonicwall" | Sonicos Enhanced Search vendor "Sonicwall" for product "Sonicos Enhanced" | < 4.0.1.1 Search vendor "Sonicwall" for product "Sonicos Enhanced" and version " < 4.0.1.1" | - |
Affected
| in | Sonicwall Search vendor "Sonicwall" | Pro 2040 Search vendor "Sonicwall" for product "Pro 2040" | - | - |
Safe
|
Sonicwall Search vendor "Sonicwall" | Sonicos Enhanced Search vendor "Sonicwall" for product "Sonicos Enhanced" | < 4.0.1.1 Search vendor "Sonicwall" for product "Sonicos Enhanced" and version " < 4.0.1.1" | - |
Affected
| in | Sonicwall Search vendor "Sonicwall" | Tz 180 Search vendor "Sonicwall" for product "Tz 180" | - | - |
Safe
|
Sonicwall Search vendor "Sonicwall" | Sonicos Enhanced Search vendor "Sonicwall" for product "Sonicos Enhanced" | < 4.0.1.1 Search vendor "Sonicwall" for product "Sonicos Enhanced" and version " < 4.0.1.1" | - |
Affected
| in | Sonicwall Search vendor "Sonicwall" | Tz 190 Search vendor "Sonicwall" for product "Tz 190" | - | - |
Safe
|