Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902801
Categoría:Web application abuses
Título:Splunk 4.0 - 4.2.4 Multiple Vulnerabilities - Active Check
Resumen:Splunk is prone to multiple vulnerabilities.
Descripción:Summary:
Splunk is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- The application allows users to perform search actions via HTTP requests without performing
proper validity checks to verify the requests. This can be exploited to execute arbitrary code
when a logged-in administrator visits a specially crafted web page.

- Certain unspecified input is not properly sanitised before being returned to the user. This can
be exploited to execute arbitrary HTML and script code in a user's browser session in context of
an affected site.

- Certain input passed to the web API is not properly sanitised before being used to access
files. This can be exploited to disclose the content of arbitrary files via directory traversal
attacks.

Vulnerability Impact:
Successful exploitation will allow remote attackers to inject
and execute arbitrary code and conduct cross-site scripting and cross-site request forgery
attacks.

Affected Software/OS:
Splunk versions 4.0 through 4.2.4.

Solution:
Update to version 4.2.5 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-4642
http://www.exploit-db.com/exploits/18245/
http://www.sec-1.com/blog/?p=233
http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf
http://www.securitytracker.com/id?1026451
http://secunia.com/advisories/47232
Common Vulnerability Exposure (CVE) ID: CVE-2011-4643
XForce ISS Database: splunk-splunkd-directory-traversal(72244)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72244
Common Vulnerability Exposure (CVE) ID: CVE-2011-4644
Common Vulnerability Exposure (CVE) ID: CVE-2011-4778
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.