Document Title: =============== SonicWall PolicyManager Module - Cross Site Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=529 Release Date: ============= 2012-09-01 Vulnerability Laboratory ID (VL-ID): ==================================== 590 Common Vulnerability Scoring System: ==================================== 2 Product & Service Introduction: =============================== Dell SonicWALL streamlines inbound and outbound email policy management. For instance, administrators can easily customize rules to simply detect and block specific types of attachments; reroute e-mail from competitors; or check all outbound e-mail for specific words and phrases. (Copy of the Vendor Homepage: http://www.sonicwall.com/us/products/364.html ) Abstract Advisory Information: ============================== The vulnerability-lab team discovered a non-persistent cross site scripting vulnerability in Sonicwalls PolicyManager. Vulnerability Disclosure Timeline: ================================== 2012-06-01: Researcher Notification & Coordination 2012-06-02: Vendor Notification 2012-06-04: Vendor Response/Feedback 2012-00-00: Vendor Fix/Patch 2012-00-00: Public or Non-Public Disclosure Discovery Status: ================= Published Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ A Cross Site Scripting Vulnerability has been detected in Sonicwalls PolicyManager. The vulnerability is located in the exception-handling of the template errors when processing to load script code out of the sn sn web context. Successful exploitation results in session hijacking, non -persistent account phishing or client side content manipulation. The bug is located in the exception-handling input/output web context of the policy editor servlet request. Vulnerable Module(s): [+] Template - Exception Handling - [SN] Input/Output Picture(s): ../1.png Proof of Concept (PoC): ======================= The client side cross site scripting vulnerability can be exploited by remote attackers with medium or high required user inter action. For demonstration or reproduce ... https://policymanager.127.0.0.1:1337/editor/servlet/editorservlet ?sn=0017C5150560%22%3E%3Ciframe%20src=a%20onload=alert%28%22VL%22%29%20%3C&event=summary.view&info=true&ui=2&locale=en Review: Exception Handling Listing - Editor Servlet SN