NICE Recording eXpress Multiple Security Vulnerabilities
BID:67677
Info
NICE Recording eXpress Multiple Security Vulnerabilities
| Bugtraq ID: | 67677 |
| Class: | Unknown |
| CVE: |
CVE-2014-4305 CVE-2014-4308 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2014 12:00AM |
| Updated: | Jun 20 2014 12:04AM |
| Credit: | Johannes Greil and Stefan Viehböck of SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
NICE Recording eXpress Multiple Security Vulnerabilities
NICE Recording eXpress is prone to the following security vulnerabilities:
1. Multiple unauthorized-access vulnerabilities
2. Multiple security-bypass vulnerabilities
3. Multiple cross-site scripting vulnerabilities
4. An HTML-injection vulnerability
5. Multiple authentication-bypass vulnerabilities
6. Multiple SQL-injection vulnerabilities
Attackers can exploit these issues to bypass certain security restrictions, gain authenticated access, obtain sensitive information, perform certain unauthorized actions, execute HTML and script code, steal cookie-based authentication credentials and access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are possible.
NICE Recording eXpress 6.3.5 is vulnerable; other versions may also be affected.
NICE Recording eXpress is prone to the following security vulnerabilities:
1. Multiple unauthorized-access vulnerabilities
2. Multiple security-bypass vulnerabilities
3. Multiple cross-site scripting vulnerabilities
4. An HTML-injection vulnerability
5. Multiple authentication-bypass vulnerabilities
6. Multiple SQL-injection vulnerabilities
Attackers can exploit these issues to bypass certain security restrictions, gain authenticated access, obtain sensitive information, perform certain unauthorized actions, execute HTML and script code, steal cookie-based authentication credentials and access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are possible.
NICE Recording eXpress 6.3.5 is vulnerable; other versions may also be affected.
Exploit / POC
NICE Recording eXpress Multiple Security Vulnerabilities
Attackers can exploit some of these issues through browser or using readily available tools. To exploit the cross-site scripting issues an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/_ifr/iframe.picker.statchannels.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.channelgroups.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.extensions.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.licenseusergroups.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.licenseusers.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.lookup.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.marks.asp?frame=[XSS]
Attackers can exploit some of these issues through browser or using readily available tools. To exploit the cross-site scripting issues an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/_ifr/iframe.picker.statchannels.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.channelgroups.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.extensions.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.licenseusergroups.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.licenseusers.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.lookup.asp?frame=[XSS]
http://www.example.com/_ifr/iframe.picker.marks.asp?frame=[XSS]
Solution / Fix
NICE Recording eXpress Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NICE Recording eXpress Multiple Security Vulnerabilities
References:
References: