Symantec Data Insight Management Console CVE-2014-3433 HTML Injection Vulnerability
BID:68161
Info
Symantec Data Insight Management Console CVE-2014-3433 HTML Injection Vulnerability
| Bugtraq ID: | 68161 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3433 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2014 12:00AM |
| Updated: | Jun 25 2014 12:00AM |
| Credit: | 2am Research team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Data Insight Management Console CVE-2014-3433 HTML Injection Vulnerability
Symantec Data Insight is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Symantec Data Insight 4.5 are vulnerable.
Symantec Data Insight is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Symantec Data Insight 4.5 are vulnerable.
Exploit / POC
Symantec Data Insight Management Console CVE-2014-3433 HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Symantec Data Insight Management Console CVE-2014-3433 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Data Insight Management Console CVE-2014-3433 HTML Injection Vulnerability
References:
References: