Landesk Management Suite 9.5 Cross Site Scripting

2015.02.03
Credit: Alex Haynes
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79


CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

CVE-2014-5360 Landesk Management Suite XSS (Cross-Site Scripting) Security Vulnerability Exploit Title: Landesk Management Suite Cross-Site scripting vulnerability Product: Landesk Management Suite Vulnerable Versions: 9.5 (possible previous versions), 9.6 Tested Version: 9.5 Advisory Publication: Feb 02, 2015 Latest Update: Feb 02, 2015 Vulnerability Type: Cross-Site Scripting [CWE-79] CVE Reference: CVE-2014-5360 Credit: Alex Haynes Advisory Details: (1) Vendor & Product Description -------------------------------- Vendor:LANDESK Product & Version:Landesk Management Suite v9.5 Vendor URL & Download:http://www.landesk.com/products/management-suite/ Product Description:"Manage all your users multi-platform desktops and mobile devices. Integrate several IT disciplinesinto a single management experience that speeds software distribution, ensures software license compliance, simplifies OS provisioning, saves power costs, provides secure remote control, and manages Mac OS X." (2) Vulnerability Details: -------------------------- The admin interface of Landesk Management Suite can be exploited by XSS attacks. Proof of concept: URL: https://<LANDESK>/remote/serverlist_grouptree.aspx?AMTVersion=+alert(5) Parameter name: AMTVersionParameter Type: GETAttack Pattern: +alert(5) (3) Advisory Timeline: ---------------------- 15/09/2014 - First Contact 19/12/2014 - Vulnerability fixed 02/02/2015 - Advisory released (4)Solution: -------------- Upgrade to version 9.6 SP1 which includes a fix for this vulnerability (5) Credits: -------------- Discovered by Alex Haynes References:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5360

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5360


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top