ManageEngine ServiceDesk Plus Multiple Cross Site Scripting Vulnerabilities
BID:49291
Info
ManageEngine ServiceDesk Plus Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 49291 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2011 12:00AM |
| Updated: | Aug 23 2011 12:00AM |
| Credit: | Juan Manuel Garcia |
| Vulnerable: |
ManageEngine ServiceDesk Plus 8.0 |
| Not Vulnerable: |
ManageEngine ServiceDesk Plus 8.0 hotfix 8015 |
Discussion
ManageEngine ServiceDesk Plus Multiple Cross Site Scripting Vulnerabilities
ManageEngine ServiceDesk Plus is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ManageEngine ServiceDesk Plus 8.0 is vulnerable.
ManageEngine ServiceDesk Plus is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ManageEngine ServiceDesk Plus 8.0 is vulnerable.
Exploit / POC
ManageEngine ServiceDesk Plus Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
Exploit input is available. Please see the references for more information.
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
Exploit input is available. Please see the references for more information.
Solution / Fix
ManageEngine ServiceDesk Plus Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ManageEngine ServiceDesk Plus Multiple Cross Site Scripting Vulnerabilities
References:
References:
- CYBSEC Advisory 2011 0801 Multiple XSS in AdventNet ManageEngine ServiceDesk Plu (CYBSEC Labs)
- ServiceDesk Plus Homepage (ManageEngine)