Hyperic HQ Enterprise Cross Site Scripting and Multiple Unspecified Security Vulnerabilities
BID:50456
Info
Hyperic HQ Enterprise Cross Site Scripting and Multiple Unspecified Security Vulnerabilities
| Bugtraq ID: | 50456 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2011 12:00AM |
| Updated: | Nov 01 2011 12:00AM |
| Credit: | Benjamin Kunz Mejri |
| Vulnerable: |
Hyperic Hyperic HQ Enterprise 4.5.1 |
| Not Vulnerable: | |
Discussion
Hyperic HQ Enterprise Cross Site Scripting and Multiple Unspecified Security Vulnerabilities
Hyperic HQ Enterprise is prone to a cross-site scripting vulnerability and multiple unspecified security vulnerabilities.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials. The impact of other issues is unknown.
These issues affect Hyperic HQ Enterprise 4.5.1; other versions may also be affected.
Hyperic HQ Enterprise is prone to a cross-site scripting vulnerability and multiple unspecified security vulnerabilities.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials. The impact of other issues is unknown.
These issues affect Hyperic HQ Enterprise 4.5.1; other versions may also be affected.
Exploit / POC
Hyperic HQ Enterprise Cross Site Scripting and Multiple Unspecified Security Vulnerabilities
An attacker may exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker may entice an unsuspecting victim to follow a malicious URI.
The following exploit is available:
An attacker may exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker may entice an unsuspecting victim to follow a malicious URI.
The following exploit is available:
Solution / Fix
Hyperic HQ Enterprise Cross Site Scripting and Multiple Unspecified Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Hyperic HQ Enterprise Cross Site Scripting and Multiple Unspecified Security Vulnerabilities
References:
References:
- Hyperic HQ Enterprise Homepage (Hyperic )
- Hyperic HQ Enterprise|E v4.5.1 - Multiple Vulnerabilities (Vulnerability Research Laboratory)