exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ME Central Desktop 7.x Cross Site Scripting

ME Central Desktop 7.x Cross Site Scripting
Posted Sep 8, 2011
Authored by Vulnerability Laboratory | Site vulnerability-lab.com

ME Central Desktop version 7.x suffers from script insertion vulnerabilities.

tags | advisory, vulnerability
SHA-256 | c23df78b8830c862cf083d2897225bfc319566f696e51c0365b9ae617163a9af

ME Central Desktop 7.x Cross Site Scripting

Change Mirror Download
Title:
======
ME Central Desktop v7.x - Multiple Persistent Vulnerabilities


Date:
=====
2011-09-06



VL-ID:
=====
36


Introduction:
=============
Desktop Central is a web-based windows desktop management software that helps in managing 1000s of desktops from a
central location. It automates the complete desktop management life cycle ranging from a simple configuration to
complex software deployment. With its network-neutral architecture, the administrator can easily manage any windows
networks like Active Directory, Workgroup, or other directory services.

(Copy of the Vendor Homepage: http://www.manageengine.com/)


Abstract:
=========
Vulnerability-Lab Team discovered mulitple persistent web vulnerabilities on Manage Engine`s Desktop Central v7.


Report-Timeline:
================
2011-09-06: Public or Non-Public Disclosure


Status:
========
Published


Affected Products:
==================
Manage Engine
Product: Central Desktop v7.5


Exploitation-Technique:
=======================
Remote


Severity:
=========
Medium


Details:
========
Multiple persistent input validation vulnerabilities are detected on Central Dekstop v7.x
Attackers can implement/inject malicious script codes(persistent) on application side of central desktop.
Successful exploitation allows an remote attacker or local low privileged user account to hijacking sessions, phish forms or manipulate vulnerable application modules.
The bugs are located n

Vulnerable Module(s):
[+] ShowPatchSettings
[+] ShowUsers
[+] Mail-Server
[+] Username - Administration Users

Pictures:
../1.png
../2.png


Risk:
=====
The security risk of the persistent vulnerabilities are estimated as medium.


Credits:
========
Vulnerability Research Laboratory


Disclaimer:
===========
The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties,
either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-
Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business
profits or special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some
states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation
may not apply. Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability-
Lab. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of
other media, are reserved by Vulnerability-Lab or its suppliers.

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close