Endian Firewall 2.4 - 'dansguardian.cgi?addrule' Cross-Site Scripting
Author: Vulnerability Research Laboratory
type: remote
platform: hardware
port:
date_added: 2012-02-27
date_updated: 2015-04-27
verified: 1
codes: CVE-2012-4923;OSVDB-85698
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/52076/info
Endian Firewall is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to execute arbitrary script on the affected server and steal cookie-based authentication credentials. Other attacks are also possible.
https://www.example.com/cgi-bin/dansguardian.cgi#addrule[XSS]