header-logo
Suggest Exploit
vendor:
Service Desk Express
by:
Nuri Fattah
7,5
CVSS
HIGH
SQL Injection, Reflected XSS
89, 79
CWE
Product Name: Service Desk Express
Affected Version From: 10.2.1.95
Affected Version To: 10.2.1.95
Patch Exists: NO
Related CWE: To be assigned
CPE: a:bmc_software:service_desk_express:10.2.1.95
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013

Multiple vulnerabilities in BMC SERVICE DESK EXPRESS (SDE) Version 10.2.1.95

Multiple vulnerabilities, including Cross-Site Scripting(XSS) and SQL injection were identified in the latest version of BMC SERVICE DESK EXPRESS. SQL injection vulnerabilities were identified in the /SDE/DashBoardGUI.aspx page with vulnerable parameters ASPSESSIONIDASSRATTQ, TABLE_WIDGET_1, TABLE_WIDGET_2, browserDateTimeInfo, browserNumberInfo, and UID. Reflected XSS vulnerabilities were identified in the /SDE/QV_admin.aspx, /SDE/QV_grid.aspx, and /SDE/commonhelp.aspx pages with vulnerable parameters SelTab, CallBack, and HelpPage respectively.

Mitigation:

No Solution has yet been provided. Please contact the vendor.
Source

Exploit-DB raw data:

Classification: NON SENSITIVE INFORMATION RELEASABLE TO THE PUBLIC

Multiple vulnerabilities in BMC SERVICE DESK EXPRESS (SDE) Version
10.2.1.95
 
Affected Product:
BMC SERVICE DESK EXPRESS (SDE) Version 10.2.1.95

Timeline:
07 June 2013      - Vulnerability found
12 June 2013      - Vendor informed
17 June 2013      - Vendor replied/confirmed & opened service ticket
 
Credits:
Nuri Fattah   of NATO / NCIRC (www.ncirc.nato.int)
 
CVE: To be assigned
 
NCIRC ID: NCIRC-2013127-02
 
Description:
Multiple vulnerabilities, including Cross-Site Scripting(XSS) and SQL
injection were identified in the latest version of BMC SERVICE DESK
EXPRESS
 
Vulnerability Details:

1. SQL injection
a. /SDE/DashBoardGUI.aspx 
vuln parameter: [ASPSESSIONIDASSRATTQ cookie]

b. /SDE/DashBoardGUI.aspx 
vuln parameter: [TABLE_WIDGET_1 cookie]
c. /SDE/DashBoardGUI.aspx 
vuln parameter: [TABLE_WIDGET_2 cookie]
d. SDE/DashBoardGUI.aspx 
vuln parameter: [browserDateTimeInfo cookie]
e. /SDE/DashBoardGUI.aspx 
vuln parameter: [browserNumberInfo cookie]
f. /SDE/login.aspx 
vuln parameter: [UID]
 
2. Reflected XSS
a. /SDE/QV_admin.aspx 
vuln parameter: [SelTab]
b. /SDE/QV_grid.aspx 
vuln parameter: [CallBack]
c. /SDE/commonhelp.aspx 
vuln parameter: [HelpPage]

example:
GET
/SDE/QV_grid.aspx?QuerySeq=1068&CondVal=1%40V1%40ADMINISTRATION%401&Call
Back=parent.parent.frames.TmInputs.callBack(doGridDataCallBack.arguments
[0]);</script><script>alert(99817)</script>&ViewType=g&bRefresh=
HTTP/1.1
 
Solution:
No Solution has yet been provided.
Please contact the vendor.