SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Mercury SiteScope 8.2 (8.1.2.0) Cross Site Scripting (XSS) Vulnerability


Arrow  SecurityAlert : 1670
Arrow  CVE : CVE-2006-5134
Arrow  CVE : CVE-2006-5122
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : Ozkan Aziz
Arrow  Published : 03.10.2006

Arrow  Affected Software : Mercury SiteScope 8.2 (8.1.2.0)



Arrow  Advisory Content :  

Whitehat.org.uk Advisory (1)

Mercury SiteScope 8.2 (8.1.2.0) Cross Site Scripting (XSS) Vulnerability

Vulnerability Type: Active code injection (XSS)

Problem Discovered: 14 September 2006

Vendor Contacted: 14 September 2006

Advisory Published: 29 September 2006

Abstract:

Mercury SiteScope is an agentless system monitoring solution designed to
ensure the availability and performance of distributed IT infrastructures
available on the Microsoft Windows Server platform as well as others.

Description:

User supplied HTML code is executed by the sitescope.

Technical Details:

Mercury sitescope 8.2 does not correctly validate user submitted input,
making it possible to execute user submitted code by the sitescope web
engine.

1) With the exception of "create new group name", any field create name
field was susceptible to exploitation.

2) Any "description" field was susceptible to exploitation.

Additional Issues:

Attempting to inject HTML code in the "new monitor description" field
resulted in a loss of connectivity to the classic interface.

Workaround:

None at present - This may be considered a low risk issue as the user will
need to be authenticated in order inject the maliciuos code, however, this
attack vector could leveraged to steal session information. The vendor has
been notified, however, has been non-responsive.

Tested Versions:

Mercury Sitescope 8.2 on Windows 2003 server - avaliable from
http://www.mercury.com

Credits: Ozkan Aziz

Greetings: Gyan (dude), Varun :) , Gerald (Wheeey), Chitt (eCrimes)

Disclaimer:

This advisory intended to be informational. No responsibility is taken for
its misuse.





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.