Imperva SecureSphere Persistent Cross-Site Scripting Vulnerability | Dell SecureWorks

Imperva SecureSphere Persistent Cross-Site Scripting Vulnerability

Advisory ID: SWRX-2011-001

Advisory Information
Title: Imperva SecureSphere Persistent Cross-Site Scripting Vulnerability
Advisory ID: SWRX-2011-001
Advisory URL: http://www.secureworks.com/research/advisories/SWRX-2011-001/
Date published: Monday, May 23, 2011
CVE: CVE-2011-0767
CVSS v2 Base Score: 4.3 (Low) (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Date of last update: Monday, May 23, 2011
Vendors contacted: Imperva
Release mode: Coordinated
Discovered by: Sean Talbot, Dell SecureWorks

Summary
A vulnerability exists in Imperva SecureSphere due to improper validation of user-controlled input. User-controllable input is not properly sanitized for illegal or malicious content prior to being stored and later returned to an administrator in dynamically generated web content. Remote attackers could leverage this issue to conduct persistent cross-site scripting attacks. When the malicious content is viewed, arbitrary script or HTML code injected into the affected database field will be executed in the SecureSphere administrative user’s browser session in the security context of the SecureSphere administrative GUI. Successful exploitation may aid an attacker in retrieving session cookies, stealing recently submitted data, or launching further attacks.

Download the PDF

PGP Signature (PC Users: You may need to right click your mouse and select "Save As")

SecureWorks CTU Public Key

Next Steps

phonepicCall Us Today
(877) 838-7947
UK +44 131 260 3044

SMB SOLUTIONS

Online Tools

  • Print this Page
  • Share This Resource






By completing this form you'll be opting in to receiving future communications about products and services from Dell SecureWorks.