exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ETAP Safety Manager 1.0.0.32 Cross Site Scripting

ETAP Safety Manager 1.0.0.32 Cross Site Scripting
Posted Sep 12, 2022
Authored by LiquidWorm | Site zeroscience.mk

ETAP Safety Manager version 1.0.0.32 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | cb949674cf6ac260ae0ea2bcfab1a0d5b6b592e39e3fccecdbd74d5a764a840e

ETAP Safety Manager 1.0.0.32 Cross Site Scripting

Change Mirror Download

ETAP Safety Manager 1.0.0.32 Remote Unauthenticated Reflected XSS


Vendor: ETAP Lighting International NV
Product web page: https://www.etaplighting.com
Affected version: 1.0.0.32

Summary: The ETAP Safety Manager (ESM) is a central managing and control
system that helps you to monitor, adjust and maintain your emergency lighting
system. Therefore each luminaire connected to your ESM network is given a
unique code. The ESM can easily identify the luminaires individually and
automatically report whether all luminaires work properly. You can either
choose between a wired or wireless network, or a combination of both. With
ESM you will not only manage your self contained or your centrally supplied
‘ETAP Battery System’ (EBS) emergency luminaires’, but also DALI emergency
units and K9 LED modules, which you can build into your luminaires. Since
your ESM system is connected to the Internet, you will always have access
to it through the World Wide Web. ESMweb™ is an ‘embedded web server’
application for monitoring an emergency lighting system, which runs in the
‘ESM web controller’. The ESMweb™ application can be accessed from any PC
in the corporate network or connected to the Internet - by a standard web
browser.

Desc: Input passed to the GET parameter 'action' is not properly sanitised
before being returned to the user. This can be exploited to execute arbitrary
HTML/JS code in a user's browser session in context of an affected site.

Tested on: Apache/2.4.41 (Ubuntu)


Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience


Advisory ID: ZSL-2022-5711
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5711.php


22.08.2022

--


PoC:

GET /json/authenticate.php?action=[XSS]&username=waddup&password=nm HTTP/1.1

{"success":false,"errorMessage":"Invalid command: $","errorCode":0,"errorInfo":"\/var\/www\/etap-root\/scripts\/class.dispatch.php(39)","rows":[]}
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close