ManageEngine OpStor Cross Site Scripting And Privilege Escalation Vulnerabilities
BID:66499
Info
ManageEngine OpStor Cross Site Scripting And Privilege Escalation Vulnerabilities
| Bugtraq ID: | 66499 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0344 CVE-2014-2670 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2014 12:00AM |
| Updated: | Apr 02 2014 01:16AM |
| Credit: | Aung Khant |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ManageEngine OpStor Cross Site Scripting And Privilege Escalation Vulnerabilities
ManageEngine OpStor is prone to cross-site scripting and privilege-escalation vulnerabilities.
Attackers can exploit these issues gain elevated privileges, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
ManageEngine Build prior to 8500 are vulnerable.
ManageEngine OpStor is prone to cross-site scripting and privilege-escalation vulnerabilities.
Attackers can exploit these issues gain elevated privileges, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
ManageEngine Build prior to 8500 are vulnerable.
Exploit / POC
ManageEngine OpStor Cross Site Scripting And Privilege Escalation Vulnerabilities
Attackers can exploit some of these issues through browser or using readily available tools. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can exploit some of these issues through browser or using readily available tools. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
ManageEngine OpStor Cross Site Scripting And Privilege Escalation Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ManageEngine OpStor Cross Site Scripting And Privilege Escalation Vulnerabilities
References:
References: