header-logo
Suggest Exploit
vendor:
Dr. Web Enterprise Server
by:
Oliver Karow
8,3
CVSS
HIGH
Remote Script Code Injection
94
CWE
Product Name: Dr. Web Enterprise Server
Affected Version From: 6.00.3.201111300
Affected Version To: 6.00.3.201111300
Patch Exists: Yes
Related CWE: N/A
CPE: drweb:enterprise_server
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012

Dr. Web Control Center Admin UI Remote Script Code Injection

Dr. Web Enterprise Security Suite is managed via a web based interface called Control Center. If an attacker suplies java script code instead of a username on the login page, this script code will be automatically executed every time an administrative user is viewing the audit log. This attack can be used to steal authentication cookies or to drive further attacks.

Mitigation:

Patch is available from vendor.
Source

Exploit-DB raw data: