SpiceWorks CVE-2014-3740 HTML Injection Vulnerability
BID:67928
Info
SpiceWorks CVE-2014-3740 HTML Injection Vulnerability
| Bugtraq ID: | 67928 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3740 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2014 12:00AM |
| Updated: | Jun 07 2014 12:00AM |
| Credit: | Dolev Farhi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SpiceWorks CVE-2014-3740 HTML Injection Vulnerability
SpiceWorks is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to SpiceWorks 7.2.00195 are vulnerable.
SpiceWorks is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to SpiceWorks 7.2.00195 are vulnerable.
Exploit / POC
SpiceWorks CVE-2014-3740 HTML Injection Vulnerability
Attackers can exploit this issue using browser.
Attackers can exploit this issue using browser.
Solution / Fix
SpiceWorks CVE-2014-3740 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.