SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Nikiara Fraud Management System XSS Vulnerability


Arrow  SecurityAlert : 7056
Arrow  CVE : CVE-2010-0706
Arrow  CWE : CWE-79
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : Yes
Arrow  Exploit Available : Yes
Arrow  Credit : Thebluegenius.
Arrow  Published : 02.03.2010

Arrow  Affected Software : subexworld:nikira_fraud_management_system



Arrow  Advisory Content :  

--------------------------------------------------------------------
# Exploit Title: Nikiara Fraud Management System XSS Vulnerability
# Date: 10 Feb 2010
# Author: thebluegenius
# Software Link: http://www.subexworld.com/fraud-management.html
# Version: All
# Tested on: Unix | Apache 2.2.4
# CVE : NA

---------------------------------------------------
"Nikara Fraud Management System" XSS vulnerability.
---------------------------------------------------
By :Thebluegenius.
Email :rajsm@isac.org.in
Blog :thebluegenius.com.
---------------------------------------------------

Description:

Nikira Fraud Management System is the next generation fraud management
solution built to deliver on a 3-step philosophy of
Detect-Investigate-Protect. Nikira detects known fraud types and patterns
of unusual behaviour, helps investigate these unusual patterns for
potential fraud, and uses the knowledge, thus generated, to upgrade and
protect against future intrusions.

The vulnerability lies at client login page. Presently this product is
deployed at over 90% of Telecom companies across the world.

------------------
Vulnerability: XSS
------------------

you can execute XSS as given below:

http://IPaddress:port/login/prompt?message=%3Cscript%3Ealert%28%27Reflected
%20XSS%27%29%3C/script%3E

-----------------------------------------------------
Greetz Fly Out to:
1] Amforked() : My good friend
2] Aodrulez : for inspiring me
3] www.OrchidSeven.com
4] www.isac.org.in



Arrow  References :

http://xforce.iss.net/xforce/xfdb/56393
http://www.securityfocus.com/bid/38311
http://www.packetstormsecurity.org/1002-exploits/nikara-xss.txt
http://secunia.com/advisories/38564




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.