ServersCheck Monitoring Software Multiple Remote Security Vulnerabilities
BID:49793
Info
ServersCheck Monitoring Software Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 49793 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2011 12:00AM |
| Updated: | Oct 05 2011 07:40PM |
| Credit: | vulnerability-lab.com |
| Vulnerable: |
ServersCheck Monitoring Software 8.8.10 ServersCheck Monitoring Software 8.8.6 |
| Not Vulnerable: |
ServersCheck Monitoring Software 8.8.11 |
Discussion
ServersCheck Monitoring Software Multiple Remote Security Vulnerabilities
ServersCheck Monitoring Software is prone to multiple remote input-validation vulnerabilities, including:
1. Multiple HTML-injection vulnerabilities
2. Multiple cross-site scripting vulnerabilities
3. A cross-site request forgery vulnerability
4. Multiple local file-include vulnerabilities
5. A security vulnerability that may allow attackers to send arbitrary SMS messages from the vendor's phone number.
An attacker can exploit these issues to execute arbitrary HTML and script code in the context of the browser or the Web server, gain access to sensitive information, send multiple SMS messages, and perform certain administrative tasks. Other attacks are also possible.
ServersCheck Monitoring Software is prone to multiple remote input-validation vulnerabilities, including:
1. Multiple HTML-injection vulnerabilities
2. Multiple cross-site scripting vulnerabilities
3. A cross-site request forgery vulnerability
4. Multiple local file-include vulnerabilities
5. A security vulnerability that may allow attackers to send arbitrary SMS messages from the vendor's phone number.
An attacker can exploit these issues to execute arbitrary HTML and script code in the context of the browser or the Web server, gain access to sensitive information, send multiple SMS messages, and perform certain administrative tasks. Other attacks are also possible.
Exploit / POC
ServersCheck Monitoring Software Multiple Remote Security Vulnerabilities
An attacker can exploit the cross-site scripting issues by enticing an unsuspecting user to follow a malicious URI. The other issues can be exploited with a browser.
The following examples are available:
An attacker can exploit the cross-site scripting issues by enticing an unsuspecting user to follow a malicious URI. The other issues can be exploited with a browser.
The following examples are available:
Solution / Fix
ServersCheck Monitoring Software Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ServersCheck Monitoring Software Multiple Remote Security Vulnerabilities
References:
References:
- Vendor Homepage (ServerCheck)