86 lines
No EOL
3.8 KiB
Text
86 lines
No EOL
3.8 KiB
Text
Trustwave SpiderLabs Security Advisory TWSL2013-024:
|
|
Cross Site Scripting (XSS) vulnerability in McAfee Superscan 4.0
|
|
|
|
Published: 08/02/2013
|
|
Version: 1.0
|
|
|
|
Vendor: McAfee (http://www.mcafee.com/)
|
|
Product: SuperScan
|
|
Version affected: v4.0
|
|
|
|
Product description:
|
|
SuperScan 4 is a Windows port scanning tool used as a TCP port scanner,
|
|
pinger and resolver.
|
|
|
|
Finding 1: Cross-Side Scripting Vulnerability
|
|
*****Credit: Piotr Duszynski @drk1wi of Trustwave SpiderLabs
|
|
CVE: CVE-2013-4884
|
|
CWE: CWE-79
|
|
|
|
It is possible to inject UTF-7 encoded XSS payload to the SuperScan 4.0
|
|
generated port scan report, through a specially crafted server response.
|
|
|
|
The injectable payload (partially UTF-7 encoded without parenthesis):
|
|
|
|
+ADw-img src=x onerror='a setter=alert,a="UTF-7-XSS";'+AD4-
|
|
|
|
XSS exploitation of McAfee SuperScan 4.0 can be automated with the
|
|
Portspoof software.
|
|
|
|
Remediation Steps:
|
|
The vendor released a fix for this vulnerability. It is recommended to
|
|
upgrade SuperScan to version 4.1.
|
|
|
|
Revision History:
|
|
07/22/13 - Vulnerability disclosed to vendor
|
|
08/01/13 - Patch released by vendor
|
|
08/02/13 - Advisory published
|
|
|
|
References:
|
|
https://kc.mcafee.com/corporate/index?page=content&id=KB78992
|
|
|
|
|
|
About Trustwave:
|
|
Trustwave is the leading provider of on-demand and subscription-based
|
|
information security and payment card industry compliance management
|
|
solutions to businesses and government entities throughout the world. For
|
|
organizations faced with today's challenging data security and compliance
|
|
environment, Trustwave provides a unique approach with comprehensive
|
|
solutions that include its flagship TrustKeeper compliance management
|
|
software and other proprietary security solutions. Trustwave has helped
|
|
thousands of organizations--ranging from Fortune 500 businesses and large
|
|
financial institutions to small and medium-sized retailers--manage
|
|
compliance and secure their network infrastructure, data communications and
|
|
critical information assets. Trustwave is headquartered in Chicago with
|
|
offices throughout North America, South America, Europe, Africa, China and
|
|
Australia. For more information, visit https://www.trustwave.com
|
|
|
|
About Trustwave SpiderLabs:
|
|
SpiderLabs(R) is the advanced security team at Trustwave focused on
|
|
application security, incident response, penetration testing, physical
|
|
security and security research. The team has performed over a thousand
|
|
incident investigations, thousands of penetration tests and hundreds of
|
|
application security tests globally. In addition, the SpiderLabs Research
|
|
team provides intelligence through bleeding-edge research and proof of
|
|
concept tool development to enhance Trustwave's products and services.
|
|
https://www.trustwave.com/spiderlabs
|
|
|
|
Disclaimer:
|
|
The information provided in this advisory is provided "as is" without
|
|
warranty of any kind. Trustwave disclaims all warranties, either express or
|
|
implied, including the warranties of merchantability and fitness for a
|
|
particular purpose. In no event shall Trustwave or its suppliers be liable
|
|
for any damages whatsoever including direct, indirect, incidental,
|
|
consequential, loss of business profits or special damages, even if
|
|
Trustwave or its suppliers have been advised of the possibility of such
|
|
damages. Some states do not allow the exclusion or limitation of liability
|
|
for consequential or incidental damages so the foregoing limitation may not
|
|
apply.
|
|
|
|
________________________________
|
|
|
|
This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under
|
|
applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying,
|
|
distribution, or use of the information contained herein (including any reliance thereon) is strictly prohibited. If
|
|
you received this transmission in error, please immediately contact the sender and destroy the material in its
|
|
entirety, whether in electronic or hard copy format. |