Vulnerable Systems:
* Dr. Web Control Center 6.00.3.201111300
Dr. Web Enterprise Security Suite is managed via a web based interface called Control Center.
If an attacker suplies java script code instead of a username on the login page, this script code will be automatically executed
every time an administrative user is viewing the audit log.
This attack can be used to steal authentication cookies or to drive further attacks.
Disclosure Timeline:
13/07/2012 - Informing Dr. Web about vulnerability
16/07/2012 - Initial response from Dr. Web
23/07/2012 - Fix successfully tested, sent response to Dr. Web
30/07/2012 - Advisory release