CVE-2008-4918
SonicOS Enhanced < 4.0.1.1 - Cross-Site Scripting via CFS Block Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4918. PoCs published by pagvac.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SonicWALL Content Filtering by injecting a malicious script into a URI, which is then reflected in the blocked-site error page. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SonicWALL Content Filtering by injecting a malicious script into a URI, which is then reflected in the blocked-site error page. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.