the last unbiased stronghold

PRTG Traffic Grapher Cross Site Scripting

PRTG Traffic Grapher Cross Site Scripting
Posted May 29, 2009
Authored by SVRT | Site security.bkis.vn

PRTG Traffic Grapher suffers from a cross site scripting vulnerability in Monitor_Bandwidth. Versions 6.2.2.977 and below are affected.

tags | advisory, xss
MD5 | c88abe0c7ca8ae9d25d905f2911427e2

PRTG Traffic Grapher Cross Site Scripting

Change Mirror Download
XSS vulnerability in 'Monitor_Bandwidth' - PRTG Traffic Grapher 
<http://blog.bkis.com/?p=704>

1. General information

PRTG Traffic Grapher is a network monitoring solution, which helps
manage and classify bandwidth usage of a network by providing accurate
results about network traffic and usage trends in graphs and tables. The
software also supports SNMP (Simple Network Management Protocol). PRTG
Traffic Grapher is available at http://www.paessler.com.

In April 2009, Bkis discovered a vulnerability in PRTG Traffic Grapher.
A hacker might exploit this hole to insert malicious codes into links to
be executed in the user’ browsers, resulting in the loss of cookies,
session, etc.

Bkis has sent the warning to PRTG Traffic Grapher developer and the
vulnerability has now been fixed.

Details : http://blog.bkis.com/?p=704
Bkis Advisory : Bkis-09-2009.
Initial vendor notification : 11/05/2009
Release Date : 28/05/2009
Update Date : 28/05/2009
Discovered by : Truong Truong Quan, Bkis.
Attack Type : XSS.
Security Rating : High.
Impact : Code Execution.
Affected Software : PRTG Traffic Grapher V6.2.2.977 and earlier versions.

2. Technical details

The identified XSS vulnerability resides in the Monitor_Bandwidth
function of the software. Specifically, the software fails to adequately
validate the input parameters.

To exploit the hole, hackers will trick users into accessing the links
containing malicious scripts. If users have already logged in PRTG
Traffic Grapher as administrators, the hackers will be able to gain the
control over the work sessions and then the complete control over PRTG
Traffice Grapher.

3. Solution
Bkis recommends that organizations, businesses using PRTG Traffic
Grapher immediately get the latest version of the software at
http://www.paessler.com/prtg6/download

Bkis

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close