Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-3036 PoC — Symantec IM Manager控制台跨站脚本攻击漏洞

Source
Associated Vulnerability
Title:Symantec IM Manager控制台跨站脚本攻击漏洞 (CVE-2009-3036)
Description:Symantec IM Manager的控制台存在跨站脚本攻击漏洞。远程攻击者可以借助未明向量,注入任意web脚本和HTML。
Readme
# CVE-2009-3036
#SpeeDr00t@Black Falcon<br>#bid38241<p><b><span style="font-size: 18pt;">Symantec IM Manager Console HTML Injection Vulnerability</span></b></p><br><br><a href="http://www.securityfocus.com/bid/38241/info">info</a><br><a href="http://www.securityfocus.com/bid/38241/discuss">discussion</a><br><a href="http://www.securityfocus.com/bid/38241/exploit">exploit</a><br><a href="http://www.securityfocus.com/bid/38241/solution">solution</a><br><a href="http://www.securityfocus.com/bid/38241/references">references</a><br><br><br><br><br>#<br>#<div id="vulnerability">
<span class="title"></span><br/><br/>
<table border="0" cellpadding="4" cellspacing="0">
<tr>
<td>
<span class="label">Bugtraq ID:</span>
</td>
<td>
				38241
			</td>
</tr>
<tr>
<td>
<span class="label">Class:</span>
</td>
<td>
				Input Validation Error
			</td>
</tr>
<tr valign="top">
<td>
<span class="label">CVE:</span>
</td>
<td>
				
					CVE-2009-3036<br/>
</td>
</tr>
<tr>
<td>
<span class="label">Remote:</span>
</td>
<td>
				Yes
			</td>
</tr>
<tr>
<td>
<span class="label">Local:</span>
</td>
<td>
				No
			</td>
</tr>
<tr>
<td>
<span class="label">Published:</span>
</td>
<td>
				Feb 18 2010 12:00AM
			</td>
</tr>
<tr>
<td>
<span class="label">Updated:</span>
</td>
<td>
				Feb 18 2010 12:00AM
			</td>
</tr>
<tr>
<td>
<span class="label">Credit:</span>
</td>
<td>
				Rafael B. Brinhosa
			</td>
</tr>
<tr valign="top">
<td>
<span class="label">Vulnerable:</span>
</td>
<td>
				
					Symantec IM Manager  8.4<br/>
					
				
					Symantec IM Manager  8.3<br/>
</td>
</tr>
<tr>
<td colspan="2">
<div class="breakline"></div>
</td>
</tr>
<tr valign="top">
<td>
<span class="label">Not Vulnerable:</span>
</td>
<td>
				
					Symantec IM Manager 8.4.13 <br/>
</td>
</tr>
</table>
</div><br><br>#<br>##no_exploit_link<br><br><br><br>#<br>#<div id="vulnerability">
<span class="title"></span><br/><br/>
	Attackers can exploit this issue with a browser.
	
		<ul>
</ul>
</div>
File Snapshot

[4.0K] /data/pocs/7bb4b4218a8d6e1d094bb1fde063dca7376a732c └── [1.9K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.