Full Disclosure mailing list archives
FD - Multiple stored XSS in FOG imaging deployment system CVE-2014-3111
From: Dolev Farhi <dolevf87 () gmail com>
Date: Tue, 13 May 2014 19:29:23 +0300
Vulnerability title: Multiple Stored Cross-Site scripting CVE: CVE-2014-3111 Vendor: FOG Project Product: FOG Imaging system Affected version: 0.27 – 0.32(latest) Fixed version: N/A Reported by: Dolev Farhi ---------------------------- VULNERABILITY Details: ---------------------------- Latest and earlier versions of fog image deployment system (0.27 through 0.32) are vulnerable to multiple persistent Cross-Site scripting in various resource management pages. By creating a printer, a new system image or a storage resource with malicious code e.g. (code) <script>alert(“sample”)</script> it is possible for a malicious user to execute client-side scripts once a user or possibly an admin attempts to load any of the resource management pages. ------------------------------------- VULNERABLE FOG RESOURCES ------------------------------------- XSS Vulnerable resources: 1.Printer Management 2.Image Management 3.Storage Management 4.User Cleanup -------------------------- PROOF OF CONCEPT -------------------------- https://www.youtube.com/watch?v=tFCLDAH35jU _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- FD - Multiple stored XSS in FOG imaging deployment system CVE-2014-3111 Dolev Farhi (May 14)