vendor:
Firewall Analyzer
by:
Michael Brooks
7.5
CVSS
HIGH
XSRF and XSS
352, 79
CWE
Product Name: Firewall Analyzer
Affected Version From: 5.0.0
Affected Version To: 5.0.0
Patch Exists: N/A
Related CWE: N/A
CPE: a:manageengine:firewall_analyzer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
ManageEngine Firewall Analyzer 5 – XSRF and XSS
This is live exploit code against the online demo. With this exploit, an attacker can execute any SQL query they want, as well as create a new administrative account. The exploit code includes an XSRF to execute arbitrary SQL queries and an XSS vulnerability.
Mitigation:
Ensure that all user input is properly sanitized and validated, and that all authentication and authorization checks are properly enforced.