CVE-2018-8716 – WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-8716
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. WSO2 Identity Server, en versiones anteriores a la 5.5.0, tiene Cross-Site Scripting (XSS) mediante el dashboard, lo que permite ataques por parte de atacantes con pocos privilegios. WSO2 Identity Sever version 5.3.0 suffers from multiple persistent cross site scripting vulnerabilities. • https://www.exploit-db.com/exploits/44531 http://packetstormsecurity.com/files/147330/WSO2-Identity-Server-5.3.0-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2018/Apr/45 http://www.securityfocus.com/archive/1/541954/100/0/threaded https://www.sec-consult.com/en/blog/advisories/multiple-stored-xss-vulnerabilities-in-wso2-carbon-and-dashboard-server/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-14995
https://notcve.org/view.php?id=CVE-2017-14995
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS. La consola de administración en WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1 y WSO2 Machine Learner 1.2.0 se ha visto afectada por un Cross-Site Scripting (XSS) persistente. • https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0257 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-14651
https://notcve.org/view.php?id=CVE-2017-14651
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. WSO2 Data Analytics Server 3.1.0 tiene una vulnerabilidad de tipo Cross-Site Scripting (XSS) en carbon/resources/add_collection_ajaxprocessor.jsp mediante los parámetros collectionName o parentPath. • https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 https://github.com/cybersecurityworks/Disclosed/issues/15 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-4315 – WSO2 Carbon 4.4.5 - Denial of Service / Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp. Vulnerabilidad de CSRF en WSO2 Carbon 4.4.5 permite a atacantes remotos secuestrar la autenticación de usuarios privilegiados para solicitudes que apagan un servidor a través de una acción de cierre de server-admin/proxy_ajaxprocessor.jsp. WSO2 Carbon version 4.4.5 suffers from a cross site request forgery vulnerability that can trigger a denial of service condition. • https://www.exploit-db.com/exploits/40242 http://hyp3rlinx.altervista.org/advisories/WSO2-CARBON-v4.4.5-CSRF-DOS.txt http://packetstormsecurity.com/files/138332/WSO2-Carbon-4.4.5-Cross-Site-Request-Forgery-Denial-Of-Service.html http://www.securityfocus.com/archive/1/539202/100/0/threaded http://www.securityfocus.com/bid/92473 https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2016-0101 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2016-4316 – WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2016-4316
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp. Múltiples vulnerabilidades de XSS en WSO2 Carbon 4.4.5 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro (1) setName a identity-mgt/challenges-mgt.jsp; el parámetro (2) webappType o (3) httpPort para webapp-list/webapp_info.jsp; el parámetro (4) dsName o (5) description para ndatasource/newdatasource.jsp; el parámetro (6) phase para viewflows/handlers.jsp; o el parámetro (7) url para ndatasource/validateconnection-ajaxprocessor.jsp. WSO2 Carbon version 4.4.5 suffers from multiple cross site scripting vulnerabilities. • https://www.exploit-db.com/exploits/40241 http://hyp3rlinx.altervista.org/advisories/WSO2-CARBON-v4.4.5-PERSISTENT-XSS-COOKIE-THEFT.txt http://packetstormsecurity.com/files/138331/WSO2-Carbon-4.4.5-Cross-Site-Scripting.html http://www.securityfocus.com/archive/1/539201/100/0/threaded http://www.securityfocus.com/bid/92473 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •