packetstormsecurity.com
http://packetstormsecurity.com/files/143780/OSNEXUS-QuantaStor-4-Information-Disclosure.html CVE-2017-9979
MEDIUM
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
Record summary
CVE-2017-9979 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript code as a parameter, aka XSS.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQuantaStor Software Defined Storage < 4.3.1 - Multiple VulnerabilitiesExploitDB exploitby VVVSecurityNot analyzed1 file
References
520170815 QuantaStor Software Define Storage mmultiple vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2017/Aug/23 vvvsecurity.com
http://www.vvvsecurity.com/advisories/vvvsecurity-advisory-2017-6943.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-9979 42517exploit
https://www.exploit-db.com/exploits/42517