Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.902801
Category:Web application abuses
Title:Splunk 4.0 - 4.2.4 Multiple Vulnerabilities - Active Check
Summary:Splunk is prone to multiple vulnerabilities.
Description:Summary:
Splunk is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- The application allows users to perform search actions via HTTP requests without performing
proper validity checks to verify the requests. This can be exploited to execute arbitrary code
when a logged-in administrator visits a specially crafted web page.

- Certain unspecified input is not properly sanitised before being returned to the user. This can
be exploited to execute arbitrary HTML and script code in a user's browser session in context of
an affected site.

- Certain input passed to the web API is not properly sanitised before being used to access
files. This can be exploited to disclose the content of arbitrary files via directory traversal
attacks.

Vulnerability Impact:
Successful exploitation will allow remote attackers to inject
and execute arbitrary code and conduct cross-site scripting and cross-site request forgery
attacks.

Affected Software/OS:
Splunk versions 4.0 through 4.2.4.

Solution:
Update to version 4.2.5 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-4642
http://www.exploit-db.com/exploits/18245/
http://www.sec-1.com/blog/?p=233
http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf
http://www.securitytracker.com/id?1026451
http://secunia.com/advisories/47232
Common Vulnerability Exposure (CVE) ID: CVE-2011-4643
XForce ISS Database: splunk-splunkd-directory-traversal(72244)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72244
Common Vulnerability Exposure (CVE) ID: CVE-2011-4644
Common Vulnerability Exposure (CVE) ID: CVE-2011-4778
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.