vendor:
InterScan Messaging Security Suite
by:
modpr0be
5.5
CVSS
MEDIUM
Stored XSS and CSRF
79, 352
CWE
Product Name: InterScan Messaging Security Suite
Affected Version From: 7.1-Build_Win32_1394
Affected Version To: 7.1-Build_Win32_1394
Patch Exists: YES
Related CWE: CVE-2012-2995, CVE-2012-2996
CPE: a:trendmicro:interscan_messaging_security_suite:7.1-build_win32_1394
Platforms Tested: Windows 2003 Standard Edition
2012
Trend Micro InterScan Messaging Security Suite Stored XSS and CSRF
Trend Micro InterScan Messaging Security Suite is susceptible to cross-site scripting (CWE-79) and cross-site request forgery (CWE-352) vulnerabilities. The proof of concept includes examples of persistent/stored XSS and non-persistent/reflected XSS as well as a cross-site request forgery exploit.
Mitigation:
Apply the latest patches and updates from the vendor.