Vulnerable Systems:
* Symantec LiveUpdate Administrator Version 2.2.2.9
Immune Systems:
* Symantec LiveUpdate Administrator Version 2.3
The webfrontend does not properly sanitize some variables before being returned to the user. If an attacker supplies a username, containing script code, at the login-page of the service, an entry in the Event Log is done, containing the "user name".
If the admin user is viewing the logfile, the script code will be executed. This can be exploited to execute arbitrary HTML and script code in a admin's browser session in context of the Web Administrator frontend.
If an attacker passes a user name like: <iframe src=http://attacker/evil.html>
in the username field he can execute CSRF attacks against the Webfrontend to change the settings.
Disclosure Timeline:
2010.07.14: Vulnerability found
2011.01.17: Sent PoC, Advisory, Disclosure policy and planned disclosure date (2011.02.04) to Vendor
2011.03.21: Update and Security Advisory release.
2011.03.22: Release of this Advisory