Icecast list.cgi User-Agent XSS

medium Nessus Plugin ID 14390

Synopsis

The remote streaming media server is hosting a CGI script that is affected by a cross-site scripting vulnerability.

Description

The remote server runs a version of Icecast that is as old or older than version 1.3.12.

This version is affected by a cross-site scripting vulnerability in the status display functionality. This issue is due to a failure of the application to properly sanitize user-supplied input.

As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed.

This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Solution

Debian has releasted a patch for the debian-based Icecast package.

Plugin Details

Severity: Medium

ID: 14390

File Name: icecast_xss.nasl

Version: 1.22

Type: remote

Published: 8/27/2004

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:icecast:icecast

Exploit Ease: No exploit is required

Vulnerability Publication Date: 8/24/2004

Reference Information

CVE: CVE-2004-0781

BID: 11021

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990

Secunia: 12344, 12361