CVE-2014-5360 Landesk Management Suite XSS (Cross-Site Scripting) Security Vulnerability Exploit Title: Landesk Management Suite Cross-Site scripting vulnerability Product: Landesk Management Suite Vulnerable Versions: 9.5 (possible previous versions), 9.6 Tested Version: 9.5 Advisory Publication: Feb 02, 2015 Latest Update: Feb 02, 2015 Vulnerability Type: Cross-Site Scripting [CWE-79] CVE Reference: CVE-2014-5360 Credit: Alex Haynes Advisory Details: (1) Vendor & Product Description -------------------------------- Vendor:LANDESK Product & Version:Landesk Management Suite v9.5 Vendor URL & Download:http://www.landesk.com/products/management-suite/ Product Description:"Manage all your users’ multi-platform desktops and mobile devices. Integrate several IT disciplinesinto a single management experience that speeds software distribution, ensures software license compliance, simplifies OS provisioning, saves power costs, provides secure remote control, and manages Mac OS X." (2) Vulnerability Details: -------------------------- The admin interface of Landesk Management Suite can be exploited by XSS attacks. Proof of concept: URL: https:///remote/serverlist_grouptree.aspx?AMTVersion=+alert(5) Parameter name: AMTVersionParameter Type: GETAttack Pattern: +alert(5) (3) Advisory Timeline: ---------------------- 15/09/2014 - First Contact 19/12/2014 - Vulnerability fixed 02/02/2015 - Advisory released (4)Solution: -------------- Upgrade to version 9.6 SP1 which includes a fix for this vulnerability (5) Credits: -------------- Discovered by Alex Haynes References:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5360