vendor:
Lynx Message Server
by:
Micro Technology Services Inc.
8,8
CVSS
HIGH
SQL Injection, Cross-Site Scripting, Session Hijacking
89, 79, 522
CWE
Product Name: Lynx Message Server
Affected Version From: 7.11.10.2
Affected Version To: 1.1.62
Patch Exists: YES
Related CWE: N/A
CPE: a:micro_technology_services_inc:lynx_message_server:7.11.10.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2012
Micro Technology Services Inc. Lynx Message Server 7.11.10.2 and/or LynxTCPService version 1.1.62 Web Interface Vulnerabilities
By submitting malicious input to certain fields, it is possible to add administrative users to the system without credentials using SQL injection, and inject code in the security context of the server. With access to session network traffic, It is also possible to hijack sessions and sniff user ID's and passwords.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in any SQL queries. Ensure that all user input is properly sanitized and validated before being used in any HTML output. Ensure that all user sessions are properly authenticated and encrypted.