exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

EJBCA 4.0.7 Cross Site Scripting / User Enumeration

EJBCA 4.0.7 Cross Site Scripting / User Enumeration
Posted Mar 11, 2012
Authored by MustLive

EJBCA versions 4.0.7 and below suffer from cross site scripting and user enumeration vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 0f7a6afa9000c6f064009e9d7b14d0a535d2af6c02184211d70657d7d27c66a3

EJBCA 4.0.7 Cross Site Scripting / User Enumeration

Change Mirror Download
Hello list!

I want to warn you about multiple security vulnerabilities in Enterprise
Java Beans Certificate Authority (EJBCA). These are Cross-Site Scripting,
Brute Force and Abuse of Functionality vulnerabilities.

EJBCA it's a PKI server. Citation from official web site: A Certification
Authority and a complete enterprise PKI management system, EJBCA is a PKI
server used to issue, manage and maintain digital certificates - with
exceptional flexibility and strength.

-------------------------
Affected products:
-------------------------

Vulnerable are EJBCA 4.0.7 and previous versions.

Developers have fixed this XSS vulnerability in new version EJBCA 4.0.8,
which has been released at 09.02.2012, but at that they decided to not fix
BF and AoF vulnerabilities, considering them as low risk. But I've suggested
them to fix them too.

----------
Details:
----------

XSS (WASC-08):

http://site/ejbca/publicweb/webdist/certdist?cmd=revoked&issuer=%3Cscript%3Ealert(document.cookie)%3C/script%3E&serno=1

Brute Force (WASC-11):

http://site/ejbca/enrol/browser.jsp

http://site/ejbca/enrol/server.jsp

http://site/ejbca/enrol/keystore.jsp

http://site/ejbca/enrol/cvcert.jsp

Abuse of Functionality (Login enumeration) (WASC-42):

Login enumeration is possible in above-mentioned four functionalities. In
these forms different messages are shown at correct and incorrect login,
which allows to enumeration logins of the users.

------------
Timeline:
------------

2012.01.17 - found vulnerabilities.
2012.02.01 - announced at my site.
2012.02.05 - informed developers.
2012.02.09 - developers released version EJBCA 4.0.8 with fixed XSS
(http://primekey.se/News/All+Releases/Release+detail/EJBCA_4.0.8_release_Feb_2012.cid3129).
2012.03.10 - disclosed at my site.

I mentioned about these vulnerabilities at my site
(http://websecurity.com.ua/5646/).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close