Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
PHPIPAM 1.4.4 Cross Site Request Forgery / Cross Site Scripting
https://3.bp.blogspot.com/-A9um4FlUYrw/WWlvH0fnNDI/AAAAAAAAILk/pA4dWsQKlcwBJHJ-2O0qL7e98i6zrXCWwCLcBGAs/s1600/h141.png
PHPIPAM version 1.4.4 suffers from cross site request forgery and cross site scripting vulnerabilities.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
PHPIPAM 1.4.4 Cross Site Request Forgery / Cross Site Scripting
https://3.bp.blogspot.com/-A9um4FlUYrw/WWlvH0fnNDI/AAAAAAAAILk/pA4dWsQKlcwBJHJ-2O0qL7e98i6zrXCWwCLcBGAs/s1600/h141.png
PHPIPAM version 1.4.4 suffers from cross site request forgery and cross site scripting vulnerabilities.
SHA-256 |
050c77ae0f13a5b4247218de44f8bf133ca516aae7da4d73aba802231bdde893Download
=====[ Tempest Security Intelligence - ADV-03/2022
]==========================
PHPIPAM - Version 1.4.4
Author: Rodolfo Tavares
Tempest Security Intelligence - Recife, Pernambuco - Brazil
=====[ Table of Contents ]==================================================
* Overview
* Detailed description
* Timeline of disclosure
* Thanks & Acknowledgements
* References
=====[ Vulnerability Information
]=============================================
* Class: Improper Neutralization of Input During Web Page Generation
('Cross-Site Scripting') [CWE-79]
* CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
* Class: Cross-Site Request Forgery (CSRF) [CWE-352]
* CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
=====[ Overview ]========================================================
* System affected: PHPIPAM - Version 1.4.4
* Software Version: Version 1.4.4 (other versions may also be affected).
* Impact: PHPIPAM 1.4.4 is vulnerable to Cross-Site Request Forgery (CSRF)
and Cross-Site Scripting (XSS) via
app/admin/subnets/find_free_section_subnets.php. An attacker can exploit
this by injecting javascript code to coerce an admin user into performing
unintended actions.
=====[ Detailed description
]=================================================
The html codes below exploit vulnerabilities in the same way due to the
fact that both forms do not contain CSRF tokens and are vulnerable to XSS
attacks. Then an attacker can host the forms on their malicious host and
trick an administrator into visiting your page. If successful, the
javascript code will execute.
* [app/admin/subnets/find_free_section_subnets.php]
Exploit PHPIPAM
method="POST">
rodnt"
/>
=====[ Timeline of disclosure
]===============================================
13/Jan/2022 - Responsible disclosure was initiated with the vendor;
14/Jan/2022 - PHPIPAM confirmed the issues;
17/Jan/2022 - The vendor fixed the issues XSS and CSRF;
24/Mar/2022 - CVE reserved as CVE-2021-46426;
25/Mar/2022 - CVE assigned [5].
=====[ Thanks & Acknowledgements ]========================================
* Tempest Security Intelligence [4]
=====[ References ]=====================================================
[1] [
https://cwe.mitre.org/data/definitions/352.html|https://cwe.mitre.org/data/definitions/352.html
]
[2] [
https://cwe.mitre.org/data/definitions/79.html|https://cwe.mitre.org/data/definitions/79.html
]
[3] [
https://github.com/phpipam/phpipam/commit/6c1f72816d6ac634e9c174057e008717d959f351|https://github.com/phpipam/phpipam/commit/6c1f72816d6ac634e9c174057e008717d959f351
]
[4] [https://www.tempest.com.br|https://www.tempest.com.br/]
[5] [
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46426|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46426
]
[6][ Thanks to Celso (CGB) =)]
=====[ EOF ]===========================================================
--
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
PHPIPAM 1.4.4 Cross Site Request Forgery / Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
SAP Application Server ABAP / ABAP Platform Code Injection / SQL Injection / Missing Authorization
___________________________
@hacking_Attack
@Hacking_Video
SAP Application Server ABAP / ABAP Platform Code Injection / SQL Injection / Missing Authorization
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
SAP Application Server ABAP / ABAP Platform Code Injection / SQL Injection / Missing Authorization
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
A Story of DOM XSS
Good day, everyone! This is my second article, this time on DOM XSS. An open redirection vulnerability was escalated to DOM XSS. If you…Continue reading on Medium »
Read more...
Good day, everyone! This is my second article, this time on DOM XSS. An open redirection vulnerability was escalated to DOM XSS. If you…Continue reading on Medium »
Read more...
Bug Bounty Diaries #2
Hi guys! I’m back with a new blog and this is great because again… I learn a lot of things, specially about DNS, IP and things like that.Continue reading on Medium »
Read more...
Hi guys! I’m back with a new blog and this is great because again… I learn a lot of things, specially about DNS, IP and things like that.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Dig Exits Stealth With $11M for Cloud Data Detection and Response Solution
CrowdStrike and CyberArk invest in Dig's seed round, which was led by Team8, alongside Merlin Ventures and chairs of MongoDB and Exabeam.
Dig Exits Stealth With $11M for Cloud Data Detection and Response Solution
CrowdStrike and CyberArk invest in Dig's seed round, which was led by Team8, alongside Merlin Ventures and chairs of MongoDB and Exabeam.
Dark Reading: Attacks/Breaches
Pro-Russian Information Operations Escalate in Ukraine War
In the three months since the war started, Russian operatives and those allied with the nation's interests have unleashed a deluge of disinformation and fake news to try and sow fear and confusion in Ukraine, security vendor says.
Pro-Russian Information Operations Escalate in Ukraine War
In the three months since the war started, Russian operatives and those allied with the nation's interests have unleashed a deluge of disinformation and fake news to try and sow fear and confusion in Ukraine, security vendor says.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
DoJ Won't Charge 'Good Faith' Security Researchers
Revised policy means security analysts won't be charged under the Computer Fraud and Abuse Act.
DoJ Won't Charge 'Good Faith' Security Researchers
Revised policy means security analysts won't be charged under the Computer Fraud and Abuse Act.
Good day, everyone! This is my second article, this time on DOM XSS. An open redirection vulnerability was escalated to DOM XSS. If you…Continue reading on Medium » (https://medium.com/@mohameddhanish98/a-story-of-dom-xss-852b6ed3bb5f?source=rss------bug_bounty-5)
Hi guys! I’m back with a new blog and this is great because again… I learn a lot of things, specially about DNS, IP and things like that.Continue reading on Medium » (https://medium.com/@noli.mtz/bug-bounty-diaries-2-44f6ae34aecd?source=rss------bug_bounty-5)