Trend Micro InterScan Messaging Security Suite Multiple Security Vulnerabilities
BID:55542
Info
Trend Micro InterScan Messaging Security Suite Multiple Security Vulnerabilities
| Bugtraq ID: | 55542 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2995 CVE-2012-2996 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2012 12:00AM |
| Updated: | Sep 13 2012 12:00AM |
| Credit: | Tom Gregory |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Trend Micro InterScan Messaging Security Suite Multiple Security Vulnerabilities
Trend Micro InterScan Messaging Security Suite is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability.
2. An HTML-injection vulnerability.
3. A cross-site request-forgery vulnerability.
An attacker can exploit these issues to steal cookie-based authentication credentials, to perform unauthorized actions in the context of a user's session, or to disclose sensitive-information.
Trend Micro InterScan Messaging Security Suite is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability.
2. An HTML-injection vulnerability.
3. A cross-site request-forgery vulnerability.
An attacker can exploit these issues to steal cookie-based authentication credentials, to perform unauthorized actions in the context of a user's session, or to disclose sensitive-information.
Exploit / POC
Trend Micro InterScan Messaging Security Suite Multiple Security Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
The following URIs and example code are available:
https://www.example.com/addRuleAttrWrsApproveUrl.imss?wrsApprovedURL=xssxss"><script>alert('XSS')</script>
https://www.example.com/initUpdSchPage.imss?src="><script>alert('XSS')</script>
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
The following URIs and example code are available:
https://www.example.com/addRuleAttrWrsApproveUrl.imss?wrsApprovedURL=xssxss"><script>alert('XSS')</script>
https://www.example.com/initUpdSchPage.imss?src="><script>alert('XSS')</script>
Solution / Fix
Trend Micro InterScan Messaging Security Suite Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Trend Micro InterScan Messaging Security Suite Multiple Security Vulnerabilities
References:
References: