Sawmill Cross Site Scripting (XSS) Vulnerability

Overview

NTA Monitor has discovered a cross site scripting (XSS) vulnerability in the Flowerfire Sawmill log analysis tool while performing a RM vulnerability test for a customer.

The web administration page for the Sawmil log analysis software is vulnerable to an XSS attack. The attacker does not need to be authenticated to perform this attack.

Vulnerability Details

Sawmill's built in webserver assumes that any query string appended to a GET request is a configuration command. This query string is not validated correctly for HTML tags so an attacker can use <script< tags to alter the output that is displayed to the browser. Possible attacks are varied, and can include creating a false login page to capture authentication details.

Example

The simple example below demonstrates the vulnerability. If the following GET request is sent to the webserver listening on the default port of 8987:

	http://host:8987/?<script>alert('vulnerable to XSS');</script>

The result of this is shown in the this screenshot:

Affected Versions

Version 7.1.13 is affected by this vulnerability, possibly older version 7 versions also are affected. The previous version 6.5.11 is not affected by this issue. At this time the windows and source code versions have been tested.

Solution

Upgrade to version 7.1.14 or newer.

Timeline

This advisory was first released on 8th September 2005.

Latest News

NTA warns online retailers to tighten their security policies to protect Christmas shoppers

27th November 2006 Card-not-present fraud is on the increase since the introduction of Chip and PIN and NTA Monitor is warning online retailers to tighten their security policies this Christmas to prevent this type of crime escalating. Read More

NTA Monitor warns companies of new security threat

8th September 2006 A concerning new cross site scripting method is beginning to appear that could allow attackers to monitor visitors' searches, usernames and passwords without their knowledge. Read More

NTA Monitor nominated to receive industry award

18th August 2006 NTA Monitor was nominated to receive the Communications News Editor's Award, which recognises excellence in the provision of products and/or services to UK ICT professionals Read More

Cisco VPN Concentrator IKE resource exhaustion DoS

26th July 2006 NTA Monitor has discovered a denial of service vulnerability in the Cisco VPN 3000 Concentrator, IOS software, PIX firewall and ASA appliance products. Read More

NTA Monitor's ike-scan tool

24th July 2006 NTA Monitor's VPN ike-scan tool has been voted the 53rd most used tool in a worldwide survey of 3,243 IT security professionals conducted by Insecure.org. Read More