← Advisories

Promise WebPAM v2.2.0.13 Multiple Remote Vulnerabilities

Medium
Advisory ID
ZSL-2012-5077
Release Date
07 March 2012
Vendor
Promise Technology, Inc. - http://www.promise.com
Affected Version
2.2.0.13
CVE
N/A
Tested On
Microsoft Windows XP Professional SP3 (EN), Jetty/4.2.23 (Windows XP/5.1 x86 java/1.4.2)
Summary

WebPAM is a web based Promise Array Management Software that's easy-to use, designed to simplify RAID storage management. WebPAM is specifically designed for Promise HBA. WebPAM can configure, manage or monitor Promise RAID products remotely from a web browser from anywhere in the world.

Description

Input passed via the parameters 'entSortOrder' and 'entSort' in 'ent_i.jsp' script are not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The parameters 'startTime' and 'endTime' in 'ent_i.jsp' are vulnerable to a XSS issue where the attacker can execute arbitrary HTML and script code in a user's browser session in context of an affected site. The parameter 'userID' in 'usr_ent.jsp' and 'usr_t.jsp' is vulnerable to HTTP Response Splitting which can be exploited to insert arbitrary HTTP headers, which are included in a response sent to the user.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
07.03.2012Initial release
08.03.2012Added reference [1], [2], [3] and [4]
13.03.2012Added reference [5] and [6]
27.03.2012Added reference [7], [8], [9] and [10]