Advisory

Imperva SecureSphere Persistent Cross-Site Scripting Vulnerability

Advisory ID: SWRX-2011-001

Advisory Information
  • Title: Imperva SecureSphere Persistent Cross-Site Scripting Vulnerability
  • Advisory ID: SWRX-2011-001
  • Date published: Monday, May 23, 2011 
  • CVE: CVE-2011-0767 
  • CVSS v2 Base Score: 4.3 (Low) (AV:N/AC:M/Au:N/C:N/I:P/A:N) 
  • Date of last update: Monday, May 23, 2011 
  • Vendors contacted: Imperva 
  • Release mode: Coordinated 
  • Discovered by: Sean Talbot, Dell SecureWorks

Summary
A vulnerability exists in Imperva SecureSphere due to improper validation of user-controlled input. User-controllable input is not properly sanitized for illegal or malicious content prior to being stored and later returned to an administrator in dynamically generated web content. Remote attackers could leverage this issue to conduct persistent cross-site scripting attacks. When the malicious content is viewed, arbitrary script or HTML code injected into the affected database field will be executed in the SecureSphere administrative user’s browser session in the security context of the SecureSphere administrative GUI. Successful exploitation may aid an attacker in retrieving session cookies, stealing recently submitted data, or launching further attacks.

Download the PDF

PGP Signature (PC Users: You may need to right click your mouse and select "Save As")

SecureWorks CTU Public Key



ABOUT THE AUTHOR
COUNTER THREAT UNIT RESEARCH TEAM

Secureworks Counter Threat Unit™ (CTU) researchers frequently serve as expert resources for the media, publish technical analyses for the security community, and speak about emerging threats at security conferences. Leveraging Secureworks’ advanced security technologies and a network of industry contacts, the CTU™ research team tracks threat actors and analyzes anomalous activity, uncovering new attack techniques and threats. This process enables CTU researchers to identify threats as they emerge and develop countermeasures that protect customers before damage can occur.
Revenir aux blogs

ESSAYEZ TAEGIS DÈS AUJOURD'HUI !

Voyez par vous-même : Demandez votre démo pour voir comment Taegis peut réduire les risques, optimiser les investissements de sécurité existants et pallier la pénurie de talents.