ManageEngine ServiceDesk Plus Cross Site Scripting and Authentication Bypass Vulnerabilities
BID:49636
Info
ManageEngine ServiceDesk Plus Cross Site Scripting and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 49636 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1509 CVE-2011-1510 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2011 12:00AM |
| Updated: | Sep 14 2011 12:00AM |
| Credit: | Matias Blanco of Core Security Technologies |
| Vulnerable: |
ManageEngine ServiceDesk Plus 8.0 |
| Not Vulnerable: | |
Discussion
ManageEngine ServiceDesk Plus Cross Site Scripting and Authentication Bypass Vulnerabilities
ManageEngine ServiceDesk Plus is prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or to generate authentication credentials to impersonate legitimate users.
ManageEngine ServiceDesk Plus 8.0 is vulnerable; other versions may also be affected.
ManageEngine ServiceDesk Plus is prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or to generate authentication credentials to impersonate legitimate users.
ManageEngine ServiceDesk Plus 8.0 is vulnerable; other versions may also be affected.
Exploit / POC
ManageEngine ServiceDesk Plus Cross Site Scripting and Authentication Bypass Vulnerabilities
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
ManageEngine ServiceDesk Plus Cross Site Scripting and Authentication Bypass Vulnerabilities
Solution:
Reports indicate that vendor patches are available; this has not been confirmed. Please contact the vendor for more information.
Solution:
Reports indicate that vendor patches are available; this has not been confirmed. Please contact the vendor for more information.
References
ManageEngine ServiceDesk Plus Cross Site Scripting and Authentication Bypass Vulnerabilities
References:
References:
- Multiples Vulnerabilities in ManageEngine ServiceDesk Plus (Core Security Technologies)
- ServiceDesk Plus Homepage (ManageEngine)