exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

NGS-sapigs-xssheap.txt

NGS-sapigs-xssheap.txt
Posted Jul 7, 2007
Authored by Mark Litchfield | Site ngssoftware.com

The SAP Internet Graphics Server suffers from a cross site scripting vulnerability and a heap overflow vulnerability.

tags | exploit, overflow, xss
SHA-256 | 765df3e3026044a65328944f7a4494ae170aee42c1789d8a3707eb8de4989b7f

NGS-sapigs-xssheap.txt

Change Mirror Download
=======
Summary
=======
Name: SAP Internet Graphics Server XSS and Heap Overflow
Release Date: 5 July 2007
Reference: NGS00487
Discover: Mark Litchfield <mark@ngssoftware.com>
Vendor: SAP
Vendor Reference: SECRES-288
Systems Affected:
Risk: Medium
Status: Fixed

========
TimeLine
========
Discovered: 4 January 2007
Released: 19 January 2007
Approved: 27 January 2007
Reported: 8 January 2007
Fixed: 18 January 2007
Published:

===========
Description
===========
The SAP IGS overflow had previously been reported. The fix went out on
the 18th Jan. Despite being reported on the 8th Jan, NGS did not receive
any credit. The advisory that was posted by the other security researcher
can be found at -
http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_SAP_IGS_Remote_Buffer_Overflow.pdf.
See attached note

The XSS issue however is still being treated by SAP as a vulnerability.

=================
Technical Details
=================
http://10.1.1.30:40180/ADM:GETLOGFILE?PARAMS=<script>alert("hello")</script>

===============
Fix Information
===============
Please ensure you have the latest version

NGSSoftware Insight Security Research
http://www.ngssoftware.com/
http://www.databasesecurity.com/
http://www.nextgenss.com/
+44(0)208 401 0070

Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close