ManageEngine Firewall Analyzer Multiple XSS

Medium Nessus Plugin ID 90445

Synopsis

The remote web server hosts an application that is affected by multiple cross-site scripting vulnerabilities.

Description

The ManageEngine Firewall Analyzer running on the remote web server is affected by multiple cross-site scripting (XSS) vulnerabilities due to improper validation of user-supplied input. A remote attacker can exploit these vulnerabilities to execute arbitrary script code in a user's browser session. The XSS vulnerabilities exist in the following scripts :

- /addDevCrd.nms
- /createAnomaly.nms
- /createProfile.do
- /customizeReportAction.nms
- /fw/addbookmark.do
- /fw/createProfile.do
- /fw/editUserFormPage.do
- /fw/graphs
- /fw/index2.do
- /fw/mindex.do
- /fw/reportFilter.do
- /fw/ResolveDNSConfig.nms
- /ResolveDNSConfig.nms
- /searchAction.do
- /uniquereport.do
- /userIPConfig.nms
- /viewListPageAction.nms

Note that Nessus has only attempted to exploit the XSS vulnerability in the viewListPageAction.nms script. Also note that a SQL injection vulnerability exists; however, Nessus did not test for this vulnerability.

Solution

Upgrade to ManageEngine Firewall Analyzer version 12.0.

See Also

http://www.nessus.org/u?1e40ddf8

Plugin Details

Severity: Medium

ID: 90445

File Name: manageengine_firewall_analyzer_pre12_multiple_xss.nasl

Version: 1.5

Type: remote

Published: 2016/04/13

Modified: 2018/08/08

Dependencies: 90447

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:H/RL:OF/RC:C

Vulnerability Information

CPE: x-cpe:/a:zohocorp:manageengine_firewall_analyzer

Required KB Items: installed_sw/ManageEngine Firewall Analyzer

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Patch Publication Date: 2016/02/23

Vulnerability Publication Date: 2016/02/19

Reference Information

EDB-ID: 39477