ManageEngine Applications Manager Multiple Cross Site Scripting and Security Vulnerabilities
BID:27443
Info
ManageEngine Applications Manager Multiple Cross Site Scripting and Security Vulnerabilities
| Bugtraq ID: | 27443 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0475 CVE-2008-0476 CVE-2008-0474 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Hector Manuel Escalona Mendoza is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
ManageEngine Applications Manager 8.1 |
| Not Vulnerable: | |
Discussion
ManageEngine Applications Manager Multiple Cross Site Scripting and Security Vulnerabilities
ManageEngine Applications Manager is prone to multiple cross-site scripting vulnerabilities, an authentication-bypass vulnerability, and an information-disclosure weakness.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or to obtain potentially sensitive information. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These issues affect Applications Manager 8.1; other versions may also be affected.
ManageEngine Applications Manager is prone to multiple cross-site scripting vulnerabilities, an authentication-bypass vulnerability, and an information-disclosure weakness.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or to obtain potentially sensitive information. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These issues affect Applications Manager 8.1; other versions may also be affected.
Exploit / POC
ManageEngine Applications Manager Multiple Cross Site Scripting and Security Vulnerabilities
Attackers may exploit these issues through a browser.
To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Attackers may exploit these issues through a browser.
To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
ManageEngine Applications Manager Multiple Cross Site Scripting and Security Vulnerabilities
Solution:
The vendor has patches available to address these issues. Please contact the vendor for information on obtaining and applying the patches. The patches are also to be included in the next service pack release of Applications Manager.
Solution:
The vendor has patches available to address these issues. Please contact the vendor for information on obtaining and applying the patches. The patches are also to be included in the next service pack release of Applications Manager.
References
ManageEngine Applications Manager Multiple Cross Site Scripting and Security Vulnerabilities
References:
References:
- Applications Manager Homepage (ManageEngine)