PT-2019-9586 · Blue Coat Systems · Asg+1
Published
2019-08-29
·
Updated
2021-07-08
·
CVE-2018-18370
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ASG versions 6.6 through 6.7.4.1
ProxySG versions 6.5 through 6.5.10.14
ProxySG versions 6.6 through 6.7.4.1
Description
A stored cross-site scripting (XSS) vulnerability in the WebFTP mode of ASG/ProxySG FTP proxy allows a remote attacker to inject malicious JavaScript code in the web listing of a remote FTP server. This can be achieved when a user accesses an FTP server via a ftp:// URL in a web browser. The attacker must be able to upload crafted files to the remote FTP server to exploit the vulnerability.
Recommendations
For ASG versions 6.6 through 6.7.4.1, update to version 6.7.4.2 or later.
For ProxySG versions 6.5 through 6.5.10.14, update to version 6.5.10.15 or later.
For ProxySG versions 6.6 through 6.7.4.1, update to version 6.7.4.2 or later.
As a temporary workaround, consider restricting access to the WebFTP mode until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asg
Proxysg