Plunet BusinessManager ACL Security Bypass and HTML Injection Vulnerabilities
BID:33153
Info
Plunet BusinessManager ACL Security Bypass and HTML Injection Vulnerabilities
| Bugtraq ID: | 33153 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2009 12:00AM |
| Updated: | Jan 09 2009 06:12PM |
| Credit: | Matteo Ignaccolo and Gabriele Zanoni from Secure Network |
| Vulnerable: |
Plunet BusinessManager 4.1 Plunet BusinessManager 0 |
| Not Vulnerable: |
Plunet BusinessManager 4.2 |
Discussion
Plunet BusinessManager ACL Security Bypass and HTML Injection Vulnerabilities
Plunet BusinessManager is prone to multiple security-bypass and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, control how the site is rendered to the user, or perform unauthorized actions as another user; other attacks may also be possible.
Versions prior to BusinessManager 4.2 are vulnerable.
Plunet BusinessManager is prone to multiple security-bypass and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, control how the site is rendered to the user, or perform unauthorized actions as another user; other attacks may also be possible.
Versions prior to BusinessManager 4.2 are vulnerable.
Exploit / POC
Plunet BusinessManager ACL Security Bypass and HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploit code and example URIs are available:
Attackers can use a browser to exploit these issues.
The following exploit code and example URIs are available:
Solution / Fix
Plunet BusinessManager ACL Security Bypass and HTML Injection Vulnerabilities
Solution:
The vendor has released BusinessManager 4.2 to address these issues. Please contact the vendor for details.
Solution:
The vendor has released BusinessManager 4.2 to address these issues. Please contact the vendor for details.
References
Plunet BusinessManager ACL Security Bypass and HTML Injection Vulnerabilities
References:
References:
- Vendor Homepage (Plunet)
- Plunet BusinessManager failure in access controls and multiple stored cross site (Matteo Ignaccolo
) - Plunet BusinessManager failure in access controls and multiple stored cross site (Matteo Ignaccolo
) - Re: Plunet BusinessManager failure in access controls and multiple stored cross (Stefano Zanero
)