CVE-2013-1823
published 2013-04-02CVE-2013-1823: Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.90%
77.4th percentile
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | subscription_asset_manager | <= 1.2.0 | — |
| redhat | subscription_asset_manager | — | — |
| redhat | subscription_asset_manager | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
vendor_redhat·2014-02-06·CVSS 4.3
CVE-2013-6674 [MEDIUM] Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.
Statement: This issue was resolved in the version of thunderbird as shipped with Red Hat Enterprise Linux 5 and 6 via RHSA-2013:1823.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Red Hat
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
vendor_redhat·2014-02-06·CVSS 4.3
CVE-2014-2018 [MEDIUM] Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Mozilla: Script execution in HTML mail replies (MFSA 2014-14)
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in a (1) OBJECT or (2) EMBED element, a related issue to CVE-2013-6674.
Statement: This issue was resolved in the version of thunderbird as shipped with Red Hat Enterprise Linux 5 and 6 via RHSA-2013:1823.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Affected
Red Hat
Katello: Notifications page Username XSS
vendor_redhat·2013-03-26·CVSS 4.3
CVE-2013-1823 [MEDIUM] CWE-79 Katello: Notifications page Username XSS
Katello: Notifications page Username XSS
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
Red Hat
Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
vendor_redhat·2013-02-19·CVSS 5.8
CVE-2013-0772 [MEDIUM] CWE-125 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image.
Statement: This issue has been addressed in firefox 24.2.0-ESR and thunderbird 24.2.0-ESR via RHSA-2013:1812 and RHSA-2013:1823.
GHSA
GHSA-4365-vm8j-8w63: Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1
ghsa_unreviewed·2022-05-17
CVE-2013-1823 [MEDIUM] CWE-79 GHSA-4365-vm8j-8w63: Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
Suricata
ET EXPLOIT Zollard PHP Exploit UA Outbound
suricata·2013-12-10
CVE-2012-1823 ET EXPLOIT Zollard PHP Exploit UA Outbound
ET EXPLOIT Zollard PHP Exploit UA Outbound
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT Zollard PHP Exploit UA Outbound"; flow:established,to_server; http.user_agent; content:"Zollard"; nocase; fast_pattern; reference:cve,2012-1823; reference:url,blogs.cisco.com/security/the-internet-of-everything-including-malware/; classtype:trojan-activity; sid:2017825; rev:6; metadata:created_at 2013_12_10, cve CVE_2012_1823, signature_severity Major, updated_at 2020_11_19;)
No public exploits indexed.
Bugzilla
CVE-2019-10173 xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)
bugzilla·2019-06-21·CVSS 9.8
CVE-2019-10173 [CRITICAL] CVE-2019-10173 xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)
CVE-2019-10173 xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)
A vulnerability was found in xstream API version 1.4.10, if the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON. This a regression of CVE-2013-7285 fixed in 1.4.7 (fixed) as of BPMS 6.0.1, the regression was introduced with xstream-1.4.10 implemented in RHPAM.
References:
https://access.redhat.com/security/cve/cve-2013-7285
Discussion:
External References:
http://x-stream.github.io/changes.html#1.4.11
---
This issue has been addressed in the following products:
Red Hat Process Automation
Via RHSA-2019:1823 https:
Bugzilla
CVE-2013-1823 Katello: Notifications page Username XSS
bugzilla·2013-03-06·CVSS 4.3
CVE-2013-1823 [MEDIUM] CVE-2013-1823 Katello: Notifications page Username XSS
CVE-2013-1823 Katello: Notifications page Username XSS
Suresh Thiru ([email protected]) of Red Hat reports:
Description of problem:
In Notifications page, the Username should escape html characters
Steps to Reproduce:
1. Create a user named FOOO
2. Go to Notifications page and notice that FOOO is in blinking mode in the page
Actual results:
FOOO is in html blinking mode in the Notifications page
Expected results:
Username should be displayed fully in Notifications page: FOOO
Discussion:
Acknowledgements:
This issue was discovered by Sureshkumar Thirugnanasambandan of the Red Hat Quality Engineering Team.
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0686 https://rhn.redhat.com/errata/RHSA-2013-0686.html
Bugzilla
CVE-2013-0772 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
bugzilla·2013-02-16·CVSS 5.8
CVE-2013-0772 [MEDIUM] CVE-2013-0772 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
CVE-2013-0772 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
Using the Address Sanitizer tool, security researcher Atte Kettunen from OUSPG found an out-of-bounds read while rendering GIF format images. This could cause a non-exploitable crash and could also attempt to render normally inaccesible data as part of the image.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-22.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Atte Kettunen as the original reporter.
Discussion:
Statement:
This issue has been addressed in firefox 24.2.0-ESR and thunderbird 24.2.0-ESR via RHSA-2013:1812 and RHSA-2013:1823.
http://rhn.redhat.com/errata/RHSA-2013-0686.htmlhttp://secunia.com/advisories/52774http://www.osvdb.org/91718https://bugzilla.redhat.com/show_bug.cgi?id=918784http://rhn.redhat.com/errata/RHSA-2013-0686.htmlhttp://secunia.com/advisories/52774http://www.osvdb.org/91718https://bugzilla.redhat.com/show_bug.cgi?id=918784
2013-04-02
Published