-----BEGIN PGP SIGNED MESSAGE-----
AUSCERT External Security Bulletin Redistribution
ESB-2008.0176 -- [Appliance]
SOPHOS Email Security Appliance Cross Site Scripting Vulnerability
22 February 2008
AusCERT Security Bulletin Summary
Product: Sophos ES4000 Email Security Appliance
Sophos ES1000 Email Security Appliance
Publisher: INFIGO IS
Operating System: Sophos Email Appliance version 184.108.40.206
Impact: Cross-site Scripting
CVE Names: CVE-2008-0838
Revision History: February 22 2008: Added CVE Number.
February 20 2008: Initial Release
- --------------------------BEGIN INCLUDED TEXT--------------------
INFIGO IS Security Advisory #ADV-2008-02-13
Title: SOPHOS Email Security Appliance Cross Site Scripting Vulnerability
Advisory ID: INFIGO-2008-02-13
Advisory URL: http://www.infigo.hr/en/in_focus/advisories/INFIGO-2008-02-13
Risk Level: Medium
Vulnerability Type: Remote
Sophos ES1000 Email Security Appliance delivers protection against spam,
viruses, Trojans, spyware and other malware. Sophos's award-winning
anti-virus engine detects all types of malware in a single, high-speed
scan. Every Sophos appliance is updated with new protection intelligence
every 5 minutes.
During an audit of Sophos ES1000 Email Security Appliance, a Cross Site
Scripting vulnerability was discovered in its web administration interface.
Administration web interface is available on the public network interface,
over HTTPS on port 18080.
Lack of input validation for 'error' and 'go' parameters of the 'Login'
This can be exploited by a malicious user to steal Sophos ES1000 Email
Security Appliance administrator credentials, and shut down the appliance,
or change its configuration.
==[ Affected Version
The vulnerability has been identified in the latest available Sophos
ES1000 and ES4000 Email Security appliances.
This vulnerability has been fixed in Sophos Email Appliance version 220.127.116.11
and above, available automatically to Sophos' customers between 14-21
February 2008. More information at
==[ PoC Exploit
==[ Vendor status
28.01.2008 - Initial contact, automated response
04.02.2008 - Repeated contact
06.02.2008 - Vendor response
07.02.2008 - Vendor status update
08.02.2008 - Vendor status update
13.02.2008 - Vendor status update
14.02.2008 - fix available
15.02.2008 - Coordinated public disclosure
Vulnerability discovered by Leon Juranic <email@example.com>.
==[ INFIGO IS Security Contact
WWW : http://www.infigo.hr/en/
E-mail : firstname.lastname@example.org
- --------------------------END INCLUDED TEXT--------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to email@example.com
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.
Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.
Previous advisories and external security bulletins can be retrieved from:
If you believe that your computer system has been compromised or attacked in
any way, we encourage you to let us know by completing the secure National IT
Incident Reporting Form at:
Australian Computer Emergency Response Team
The University of Queensland
Internet Email: firstname.lastname@example.org
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
-----BEGIN PGP SIGNATURE-----
-----END PGP SIGNATURE-----