Document Title:
===============
SonicWall Viewpoint v6.0 SP2 - Multiple Web Vulnerabilities
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=195
Release Date:
=============
2011-09-27
Vulnerability Laboratory ID (VL-ID):
====================================
195
Product & Service Introduction:
===============================
SonicWALL® ViewPoint™ ist ein benutzerfreundliches webbasiertes Reporting-Tool, das die Sicherheitsprodukte und -dienste
von SonicWALL vollständig unterstützt und erweitert. Es kann flexibel als Software oder virtuelle Appliance implementiert
werden. Umfassende Reporting-Funktionen geben Administratoren einen unmittelbaren Einblick in den Zustand, die Leistung und
die Sicherheit ihres Netzwerks. Mithilfe der anpassbaren Übersichtsanzeige und einer Vielzahl von Verlaufsberichten unterstützt
SonicWALL ViewPoint Unternehmen aller Größen dabei, Netzwerknutzung und Sicherheitsaktivitäten zu überwachen und die
Webnutzung anzuzeigen.
(Copy of the Vendor Homepage: http://www.sonicwall.com/de/Centralized_Management_and_Reporting.html)
Abstract Advisory Information:
==============================
Vulnerability-Lab Team discovered multiple Input Validation Vulnerabilities on SonicWalls Viewpoint appliance/application.
Vulnerability Disclosure Timeline:
==================================
2011-05-16: Vendor Notification
2011-06-21: Vendor Response/Feedback
2011-09-26: Public or Non-Public Disclosure
2011-10-01: Vendor Fix/Patch
Discovery Status:
=================
Published
Affected Product(s):
====================
DELL SonicWall
Product: ViewPoint Application 6.0 SP2
Exploitation Technique:
=======================
Remote
Severity Level:
===============
Medium
Technical Details & Description:
================================
1.1
Multiple persistent input validation vulnerabilities are detected on sonicwalls viewpoint & global management application.
The persistent vulnerability allows an local low privileged user account to manipulate specific application modules or content requests.
Vulnerable Module(s): (Persistent)
[+] SonicWall Training (Titel; RSS_URL;Logs Mail)
[+] Current Sessions (Titel)
[+] Add Componente
[+] Report Layout / Template
[+] Scheduled Reports
[+] Security Dashboard
[+] Custom Report – Website Filtering
[+] SonicWall Today
[+] SonicToday Pagetitle
[+] SonicToday log title
1.2
Multiple non-persistent input validation vulnerabilities are detected on sonicwalls viewpoint & global management application.
The non persistent vulnerability allows an remote attacker to hijack customer/admin session with high required user inter action.
Vulnerable Module(s): (Non Persistent)
[+] FTP Usage / Top Users of FTP / Web Usage Top Sites
[+] Show Logs
[+] Description
[+] Security Dashboard
Picture(s):
../ive1.png
../ive2.png
../ive3.png
Proof of Concept (PoC):
=======================
The vulnerabilities can be exploited by remote attackers or local low privileged user accounts.
For demonstration or reproduce ...
Section: Top FTP Users
" />
Section: License Viewpoint