ID

VAR-201702-0415


CVE

CVE-2016-1566


TITLE

Guacamole File browser cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2016-007113

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. NOTE: this vulnerability was fixed in guacamole.war on 2016-01-13, but the version number was not changed. Guacamole is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input. Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible. Guacamole 0.9.8 and 0.9.9 are vulnerable

Trust: 1.89

sources: NVD: CVE-2016-1566 // JVNDB: JVNDB-2016-007113 // BID: 96366

AFFECTED PRODUCTS

vendor:apachemodel:guacamolescope:eqversion:0.9.8

Trust: 1.8

vendor:apachemodel:guacamolescope:eqversion:0.9.9

Trust: 1.8

vendor:guac devmodel:guacamolescope:eqversion:0.9.8

Trust: 0.6

vendor:guac devmodel:guacamolescope:eqversion:0.9.9

Trust: 0.6

vendor:guacamolemodel:guacamolescope:eqversion:0.9.9

Trust: 0.3

vendor:guacamolemodel:guacamolescope:eqversion:0.9.8

Trust: 0.3

sources: BID: 96366 // JVNDB: JVNDB-2016-007113 // CNNVD: CNNVD-201702-008 // NVD: CVE-2016-1566

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-1566
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-1566
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201702-008
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2016-1566
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2016-1566
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.3
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: JVNDB: JVNDB-2016-007113 // CNNVD: CNNVD-201702-008 // NVD: CVE-2016-1566

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.8

sources: JVNDB: JVNDB-2016-007113 // NVD: CVE-2016-1566

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201702-008

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201702-008

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-007113

PATCH

title:Top Pageurl:http://guacamole.apache.org/

Trust: 0.8

title:Security Advisory - Stored XSS (CVE-2016-1566 / GUAC-1465)url:https://sourceforge.net/p/guacamole/news/2016/02/security-advisory---stored-xss-cve-2016-1566--guac-1465/

Trust: 0.8

title:Apache Guacamole Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=67398

Trust: 0.6

sources: JVNDB: JVNDB-2016-007113 // CNNVD: CNNVD-201702-008

EXTERNAL IDS

db:NVDid:CVE-2016-1566

Trust: 2.7

db:JVNDBid:JVNDB-2016-007113

Trust: 0.8

db:CNNVDid:CNNVD-201702-008

Trust: 0.6

db:BIDid:96366

Trust: 0.3

sources: BID: 96366 // JVNDB: JVNDB-2016-007113 // CNNVD: CNNVD-201702-008 // NVD: CVE-2016-1566

REFERENCES

url:https://sourceforge.net/p/guacamole/news/2016/02/security-advisory---stored-xss-cve-2016-1566--guac-1465/

Trust: 1.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-1566

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-1566

Trust: 0.8

url:https://sourceforge.net/projects/guacamole/

Trust: 0.3

sources: BID: 96366 // JVNDB: JVNDB-2016-007113 // CNNVD: CNNVD-201702-008 // NVD: CVE-2016-1566

CREDITS

Guacamole

Trust: 0.3

sources: BID: 96366

SOURCES

db:BIDid:96366
db:JVNDBid:JVNDB-2016-007113
db:CNNVDid:CNNVD-201702-008
db:NVDid:CVE-2016-1566

LAST UPDATE DATE

2024-11-23T22:45:46.831000+00:00


SOURCES UPDATE DATE

db:BIDid:96366date:2017-03-07T02:06:00
db:JVNDBid:JVNDB-2016-007113date:2017-02-10T00:00:00
db:CNNVDid:CNNVD-201702-008date:2021-05-08T00:00:00
db:NVDid:CVE-2016-1566date:2024-11-21T02:46:39.130

SOURCES RELEASE DATE

db:BIDid:96366date:2017-02-02T00:00:00
db:JVNDBid:JVNDB-2016-007113date:2017-02-10T00:00:00
db:CNNVDid:CNNVD-201702-008date:2017-02-03T00:00:00
db:NVDid:CVE-2016-1566date:2017-02-02T15:59:00.140