CVE-2007-3593
ManageEngine NetFlow Analyzer 5 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2007-3593. PoCs published by Lostmon.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 5 by injecting malicious JavaScript via the 'view' parameter in the URL. The payload includes HTML and JavaScript to display a message and steal cookie-based authentication credentials.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c) netflow/jspui/index.jsp, and the (4) rtype parameter in (d) netflow/jspui/selectDevice.jsp and (e) netflow/jspui/customReport.jsp. NOTE: it was later reported that vector 3 also affects 7.5 build 7500.
Exploits (5)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 5 by injecting malicious JavaScript via the 'view' parameter in the URL. The payload includes HTML and JavaScript to display a message and steal cookie-based authentication credentials.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 5 by injecting malicious script code via the 'rtype' parameter in the URL. The payload includes HTML and JavaScript designed to steal cookie-based authentication credentials.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 5 by injecting arbitrary script code via the 'rtype' parameter in the customReport.jsp page. The payload includes HTML and JavaScript to display a message and steal cookie-based authentication credentials.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 5 by injecting malicious JavaScript via the 'alpha' parameter in the applicationList.jsp page. The payload redirects users to a malicious site and steals cookie-based authentication credentials.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in NetFlow Analyzer 5 by injecting malicious JavaScript via the 'task' parameter in the URL. The payload redirects users to a malicious site and displays an alert with the document cookie.