Multiple Dell SonicWALL Products '/sgms/mainPage' Page Cross Site Scripting Vulnerability
BID:65498
Info
Multiple Dell SonicWALL Products '/sgms/mainPage' Page Cross Site Scripting Vulnerability
| Bugtraq ID: | 65498 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0332 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2014 12:00AM |
| Updated: | Mar 19 2015 09:15AM |
| Credit: | William Costa |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Dell SonicWALL Products '/sgms/mainPage' Page Cross Site Scripting Vulnerability
Multiple Dell SonicWALL products are prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products prior to version 7.1 SP1 are vulnerable:
Dell SonicWALL Global Management System
Dell SonicWALL Analyzer
Dell SonicWALL Universal Management Appliance E5000
Multiple Dell SonicWALL products are prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products prior to version 7.1 SP1 are vulnerable:
Dell SonicWALL Global Management System
Dell SonicWALL Analyzer
Dell SonicWALL Universal Management Appliance E5000
Exploit / POC
Multiple Dell SonicWALL Products '/sgms/mainPage' Page Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
https://www.example.com/sgms/mainPage?page=genNetwork&screenid=1002&manager=ScreenDisplayManager&level=1&node_id=[XSS]&screenid=1002&unused=&help_url=&node_name=Instance View&unitType=1&searchBySonicwall=0
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
https://www.example.com/sgms/mainPage?page=genNetwork&screenid=1002&manager=ScreenDisplayManager&level=1&node_id=[XSS]&screenid=1002&unused=&help_url=&node_name=Instance View&unitType=1&searchBySonicwall=0