exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

TMCM-XSS.txt

TMCM-XSS.txt
Posted Jun 27, 2006
Authored by Darren Bounds

The Trend Micro Control Manager is vulnerable to a persistent, unauthenticated cross site scripting attack. Version 3.5 is affected. Earlier versions may also be affected.

tags | advisory, xss
SHA-256 | c3d1d3bbbf78085ec649a55ccb2a77773e6db22a4402d09da1ae786cd449f05e

TMCM-XSS.txt

Change Mirror Download
Trend Micro Control Manager (TMCM) Persistent XSS Vulnerability
June 23, 2006

Product Overview:
Trend Micro Control Manager is a centralized, web-based outbreak
management console designed to simplify enterprise-wide coordination
of outbreak security actions and management of Trend Micro products
and services. Trend Micro Control Manager acts as a central command
center for deployment of Trend Micro's threat-specific expertise
across the network and to select third-party products to proactively
manage outbreaks.

Vulnerability Details:
Trend Micro Control Manager is vulnerable to a persistent,
unauthenticated XSS attack. This vulnerability can be exploited by an
attacker to obtain full administrative access to the TMCM
administration console, compromising the integrity of the corporate
enterprise anti-virus infrastructure.

This vulnerability stems from TMCMs failure to sanitize audit log
content when displaying it through the management console. As such, an
attacker may inject script into the username field at the login page.
Any logins, failed or successful are then available in the Access Log
for execution when viewed by an authenticated administrative user.

Affected Versions:
Trend Micro Control Manager 3.5
Olders versions may also be affected.

Workarounds:
Control network access to the TMCM web console.

References:
http://www.trendmicro.com/en/products/management/tmcm/

Vendor was contacted on several occasions with no response.


--

Thank you,
Darren Bounds
Login or Register to add favorites

File Archive:

February 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    11 Files
  • 2
    Feb 2nd
    9 Files
  • 3
    Feb 3rd
    5 Files
  • 4
    Feb 4th
    0 Files
  • 5
    Feb 5th
    0 Files
  • 6
    Feb 6th
    0 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close