ManageEngine OpStor Cross Site Scripting, HTML Injection and SQL Injection Vulnerabilities
BID:55070
Info
ManageEngine OpStor Cross Site Scripting, HTML Injection and SQL Injection Vulnerabilities
| Bugtraq ID: | 55070 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2012 12:00AM |
| Updated: | Aug 17 2012 12:00AM |
| Credit: | Ibrahim El-Sayed |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ManageEngine OpStor Cross Site Scripting, HTML Injection and SQL Injection Vulnerabilities
ManageEngine OpStor is prone to cross-site scripting, HTML-injection, and SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to run malicious HTML and script codes, to steal cookie-based authentication credentials, to compromise the application, to access or modify data, or to exploit latent vulnerabilities in the underlying database.
ManageEngine OpStor 7.4 is vulnerable; other versions may be affected.
ManageEngine OpStor is prone to cross-site scripting, HTML-injection, and SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to run malicious HTML and script codes, to steal cookie-based authentication credentials, to compromise the application, to access or modify data, or to exploit latent vulnerabilities in the underlying database.
ManageEngine OpStor 7.4 is vulnerable; other versions may be affected.
Exploit / POC
ManageEngine OpStor Cross Site Scripting, HTML Injection and SQL Injection Vulnerabilities
An attacker can exploit these issues through a browser. An attacker must trick an unsuspecting victim into following a malicious URI to exploit the cross-site scripting issues.
The following example URIs are available.
http://www.example.com/raidMaps.do?raidId=10000&name=000123456789'+AND+'1'='1')-- -
http://www.example.com/availability730.do?days=>"<iframe src=http://www.vuln-lab.com onload=alert("XSS")></iframe>&name=>"<iframe src=http://www.vuln-lab.com onload=alert("XSS")></iframe>
An attacker can exploit these issues through a browser. An attacker must trick an unsuspecting victim into following a malicious URI to exploit the cross-site scripting issues.
The following example URIs are available.
http://www.example.com/raidMaps.do?raidId=10000&name=000123456789'+AND+'1'='1')-- -
http://www.example.com/availability730.do?days=>"<iframe src=http://www.vuln-lab.com onload=alert("XSS")></iframe>&name=>"<iframe src=http://www.vuln-lab.com onload=alert("XSS")></iframe>
Solution / Fix
ManageEngine OpStor Cross Site Scripting, HTML Injection and SQL Injection Vulnerabilities
Solution:
Vendor patch is available. Please see the references for more information.
Solution:
Vendor patch is available. Please see the references for more information.
References
ManageEngine OpStor Cross Site Scripting, HTML Injection and SQL Injection Vulnerabilities
References:
References: