[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAEWuDG4NGsT=UMEzwf=Y2YBhvoN_EJvb_VzUnY7cC0S4ct4hBg@mail.gmail.com>
Date: Mon, 30 Apr 2018 23:00:46 +0200
From: n0ipr0cs <franciscojaviersantiagovazquez@...il.com>
To: fulldisclosure@...lists.org
Subject: [FD] XSS in Flexense DiskSorter, affects all versions
*Description:*
URL: localhost/
Affected Component: */?n0ipr0cs<script>alert('XSS')</script>n0ipr0cs=1*
*Vulnerability Type:*
Cross Site Scripting https://cwe.mitre.org/data/definitions/79.html
*Vendor of Product: *
Flexense DiskSorter
*Version: *
from v9.5.12 to v10.7.
*Attack Type: *
Remote
*Impact: *
This attack allows an attacker code execution. The vulnerability affects
the confidentiality of personal data, possible theft of confidential
information, for example credentials of session, cookie information,
personal information, or a possible loss of control of the PC.
*About:*
DiskSorter is a file classification solution allowing one to classify files
in local disks, network shares, NAS devices and enterprise storage systems.
Users are provided with the ability to gain an in-depth visibility into
which types of files are using most of the disk space, save reports and
perform file management operations on categories of files.
*Credits:*
This vulnerability have been discovered by
Francisco Javier Santiago Vázquez aka "n0ipr0cs"
https://es.linkedin.com/in/francisco-javier-santiago-v%C3%A1zquez-1b654050
https://twitter.com/n0ipr0cs
*Disclosure Timeline:*
April 07, 2018: Vulnerability acquired by Francisco Javier Santiago
Vázquez. aka "n0ipr0cs".
April 07, 2018: Responsible disclosure to Flexense Security Team.
April 18, 2018: Second Message Responsible disclosure to Flexense Security
Team.
April 24, 2018: The vulnerability has been fixed.The new product version
(v10.8) fixes a number of bugs and security vulnerabilities, this include
CVE-2018-10568
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10568>
April 30, 2018: Disclosure of vulnerability.
*Link:* http://blog.n0ipr0cs.io/post/2018/04/29/XSS-Flexense-D
iskBoss-Enterprise-all-versions
<http://blog.n0ipr0cs.io/post/2018/04/29/XSS-Flexense-DiskBoss-Enterprise-all-versions>
<https://about.me/javiersantiagovazquez?promo=email_sig&utm_source=product&utm_medium=email_sig&utm_campaign=gmail_api&utm_content=thumb>
F. Javier Santiago Vázquez
about.me/javiersantiagovazquez
<https://about.me/javiersantiagovazquez?promo=email_sig&utm_source=product&utm_medium=email_sig&utm_campaign=gmail_api&utm_content=thumb>
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists