ServersCheck Monitoring Software Multiple HTML Injection Vulnerabilities
BID:55903
Info
ServersCheck Monitoring Software Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 55903 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2012 12:00AM |
| Updated: | Oct 10 2012 12:00AM |
| Credit: | loneferret of Offensive Security |
| Vulnerable: |
ServersCheck Monitoring Software 9.0.14 ServersCheck Monitoring Software 9.0.13 ServersCheck Monitoring Software 9.0.12 |
| Not Vulnerable: |
ServersCheck Monitoring Software 9.0.17 ServersCheck Monitoring Software 9.0.16 |
Discussion
ServersCheck Monitoring Software Multiple HTML Injection Vulnerabilities
ServersCheck Monitoring Software is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
ServersCheck Monitoring Software versions prior to 9.0.16 are vulnerable.
ServersCheck Monitoring Software is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
ServersCheck Monitoring Software versions prior to 9.0.16 are vulnerable.
Exploit / POC
ServersCheck Monitoring Software Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues through a web browser.
Attackers can exploit these issues through a web browser.
Solution / Fix
ServersCheck Monitoring Software Multiple HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ServersCheck Monitoring Software Multiple HTML Injection Vulnerabilities
References:
References:
- Monitoring Software Homepage (ServersCheck)
- ServersCheck Homepage (ServersCheck)
- ServersCheck Monitoring Software Release History (ServersCheck)
- ServersCheck Monitoring Software v9.0.12 / 9.0.14 - Stored XSS (loneferret of Offensive Security)