Symantec Security Information Manager Cross Site Scripting and HTML Injection Vulnerabilities
BID:60797
Info
Symantec Security Information Manager Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 60797 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1614 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2013 12:00AM |
| Updated: | Jul 01 2013 12:00AM |
| Credit: | Hacktive Security Research and Development team |
| Vulnerable: |
Symantec Security Information Manager 4.8.0 Symantec Security Information Manager 4.7.0 |
| Not Vulnerable: |
Symantec Security Information Manager 4.8.1 |
Discussion
Symantec Security Information Manager Cross Site Scripting and HTML Injection Vulnerabilities
Symantec Security Information Manager is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Symantec Security Information Manager 4.8.1 are vulnerable.
Symantec Security Information Manager is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Symantec Security Information Manager 4.8.1 are vulnerable.
Exploit / POC
Symantec Security Information Manager Cross Site Scripting and HTML Injection Vulnerabilities
An attacker can exploit these issues using a browser. To exploit a cross-site scripting vulnerability, the attacker will entice an unsuspecting user to visit a specially crafted URL.
An attacker can exploit these issues using a browser. To exploit a cross-site scripting vulnerability, the attacker will entice an unsuspecting user to visit a specially crafted URL.
Solution / Fix
Symantec Security Information Manager Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Security Information Manager Cross Site Scripting and HTML Injection Vulnerabilities
References:
References:
- Symantec Home Page (Symantec)
- Symantec Security Information Manager Homepage (Symantec)
- SYM13-006: Symantec Security Information Manager Console Security Issues (Symantec)