3Com Intelligent Management Center Multiple Vulnerabilities
BID:40298
Info
3Com Intelligent Management Center Multiple Vulnerabilities
| Bugtraq ID: | 40298 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2010 12:00AM |
| Updated: | May 20 2010 12:00AM |
| Credit: | Richard Brain of ProCheckUp |
| Vulnerable: |
3Com Intelligent Management Center (IMC) 3.3.9 R2 606 3Com Intelligent Management Center (IMC) 3.3 SP1 R2 606 |
| Not Vulnerable: |
3Com Intelligent Management Center (IMC) 3.3 SP2 R2 606 |
Discussion
3Com Intelligent Management Center Multiple Vulnerabilities
3Com Intelligent Management Center is prone to multiple directory-traversal, cross-site scripting, and information-disclosure vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues will allow an attacker to traverse through arbitrary directories and gain access to sensitive information, view local files in the context of the webserver process, and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
3Com Intelligent Management Center 3.3 SP1 and 3.3.9 are vulnerable; other versions may also be affected.
3Com Intelligent Management Center is prone to multiple directory-traversal, cross-site scripting, and information-disclosure vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues will allow an attacker to traverse through arbitrary directories and gain access to sensitive information, view local files in the context of the webserver process, and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
3Com Intelligent Management Center 3.3 SP1 and 3.3.9 are vulnerable; other versions may also be affected.
Exploit / POC
3Com Intelligent Management Center Multiple Vulnerabilities
An attacker can exploit the directory-traversal and information disclosure vulnerabilities with a web browser. Attackers can exploit the cross-site scripting vulnerability by enticing an unsuspecting victim into following a malicious URI.
The following example URIs are available:
An attacker can exploit the directory-traversal and information disclosure vulnerabilities with a web browser. Attackers can exploit the cross-site scripting vulnerability by enticing an unsuspecting victim into following a malicious URI.
The following example URIs are available:
Solution / Fix
3Com Intelligent Management Center Multiple Vulnerabilities
Solution:
These issues may be fixed in 3Com's Intelligent Management Centre 3.3SP2 (R2606P13). Please see the references for details.
Solution:
These issues may be fixed in 3Com's Intelligent Management Centre 3.3SP2 (R2606P13). Please see the references for details.
References
3Com Intelligent Management Center Multiple Vulnerabilities
References:
References: