Multiple Dell packetTrap psa html Injection Vulnerabilities
Multiple Dell packetTrap psa html Injection Vulnerabilities
Release date:
Updated on: 2013-07-19
Affected Systems:
Dell packetTrap PSA
Description:
--------------------------------------------------------------------------------
Bugtraq id: 61318
Dell packetTrap PSA is an IT management and network monitoring software.
Dell packetTrap PSA 7.1 has multiple HTML Injection Vulnerabilities. After successful exploitation, attackers can run the HTML and script code provided by attackers in the context of the affected browser to perform unauthorized database operations.
<* Source: Benjamin Kunz Mejri
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Review: Contract Overview & Edit-Listing
<Div class = "objectHead">
<H1> Contract: <span id = "lblPageTitle"> "> <[persistent injected script code!]> </Span> <H2> <a href = "https://www.example.com/customers/customer.aspx? CustomerId = 33628564 ";> <span
Id = "lblCustomerName"> Sample Customer </span> </a> </Div>
...&
<Td style = "width: 130px;" class = "formLabel"> Contract Name: </td>
<Td style = "width: auto;">
<Span id = "txtContractName"> "> <[persistent injected script code!]> </Span>
</Td>
</Tr>
Review: Equipment Item Overview & Edit-Listing
<Td class = "formLabel">
Purchase Info .:
</Td>
<Td>
<Span id = "lblPurchaseInfo"> Purchased on Dec 11,201 2 from "> <[persistent injected script code!]> </Span>
</Td>
</Tr>
Review: Import Customer Equipment Records Overview-Listing
</Tr> <tr class = "gridItem" valign = "top">
<Td> <! --? Php </td -->
</Td> </tr> <tr class = "gridItem" valign = "top">
<Td> phpinfo (); </td> O_O
</Tr> <tr class = "gridItem" valign = "top">
<Td >?> </Td>
</Tr> <tr class = "gridItem" valign = "top">
<Td> <[persistent injected script code!] (</Td ">
</Tr>
</Table>
Review: Labor Rate Details-Listing
<Td class = "formLabel">
Name/No.: </td>
<Td>
<Span id = "lblItemNo"> "> <[persistent injected script code!]> </Span>
</Td>
</Tr>
<Tr>
<Td class = "formLabel"> Description: </td>
<Td>
<Span id = "lblDescription"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
...&
<Td class = "formLabel"> Account Name: </td>
<Td>
<Span id = "lblAccountName"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
Review: Materials Item Overview-Listing
<Span id = "lblItemNo"> "> <[persistent injected script code!] ">
</Td>
</Tr>
<Tr>
<Td class = "formLabel">
Description: </td>
<Td>
<Span id = "lblDescription"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
...&
<Table border = "0" cellpadding = "4" cellspacing = "0" width = "100%">
<Tbody> <tr>
<Td colspan = "2">
<Hr> </td>
</Tr>
<Tr>
<Td style = "width: 130px;" class = "formLabel"> Manufacturer: </td>
<Td style = "width: auto;">
<Span id = "lblMfrName"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
<Tr> <td class = "formLabel"> Mfr. Item No.: </td>
<Td>
<Span id = "lblMfrItemNo"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
<Tr> <td class = "formLabel"> Mfr. Item Desc.: </td>
<Td>
<Span id = "lblMfrDescription"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
...&
<Tr> <td class = "formLabel"> Account Name: </td>
<Td>
<Span id = "lblAccountName"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
<Tr>
<Td colspan = "2">
<Hr> </td>
</Tr>
<Tr>
<Td class = "formLabel"> Id: </td>
<Td>
<Span id = "lblItemId"> 33583304 </span> </td>
</Tr>
<Tr>
<Td class = "formLabel"> Created: </td>
<Td>
<Span id = "lblCreated"> by the storm on Dec 9, 2012 at PM </span> </td>
</Tr>
<Tr>
<Td colspan = "2">
<Hr> </td>
</Tr>
<Tr>
<Td class = "formLabel"> Notes: </td>
<Td>
<Span id = "lblNotes"> "> <[persistent injected script code!]> </Span> </td>
</Tr>
Review: New customer Account Details-Listing
<Tbody> <tr>
<Td style = "width: 130px;">
<Strong> Primary Contact: </strong>
</Td>
<Td style = "width: auto;">
<Span id = "lblPrimaryContact"> <a href = "https://www.example.com/customers/contact.aspx? CustomerId = 33628565 &;
ContactId = 33637457 ">"> <iframe src = http: // www. "> <iframe src = http: // www. </a> ,()-,
<A href = "mailto:";> <[persistent injected script code!]> ">"> <[Persistent injected script code!]> </A> </span>
</Td>
</Tr>
<Tr>
<Td>
<Strong> Primary Location: </strong>
</Td>
<Td>
<Span id = "lblPrimaryLocation"> <a href = "https://www.example.com/customers/location.aspx? CustomerId = 33628565 &;
LocationID = 33649992 ">"> <[persistent injected script code!] </A>, "> <[persistent injected script code!]>
(<A href = "https://www.example.com/tools/getMap.aspx? CustomerLocationId = 33649992 "; class =" map-link "> Get
Map </a>) </span>
</Td>
</Tr>
</Tbody>
Review: Report-Listing
<Div class = "ReportHeader">
<H1> <span id = "lblPageTitle"> "> <[persistent injected script code!]> </Span> </Div>
<Div class = "ReportBody">
<Input name = "TempSortCol" id = "TempSortCol" type = "hidden">
<Input name = "TempSortOrder" id = "TempSortOrder" type = "hidden">
<Div id = "ReportParameters" class = "ReportParameters2">
<Div id = "StandardFilters_ReportParameters">
<Div class = "ParameterGroupHead">
<Span class = "ui-corner-tr"> Time Frame </span>
</Div>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Dell
----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.dell.com/support/drivers/us/en/