ID

VAR-E-200903-0140


CVE

cve_id:CVE-2007-4475

Trust: 2.4

sources: BID: 34310 // PACKETSTORM: 82972 // EXPLOIT-DB: 32879 // EDBNET: 54386

EDB ID

32879


TITLE

SAP MaxDB 7.4/7.6 - 'webdbm' Multiple Cross-Site Scripting Vulnerabilities - Windows remote Exploit

Trust: 0.6

sources: EXPLOIT-DB: 32879

DESCRIPTION

SAP MaxDB 7.4/7.6 - 'webdbm' Multiple Cross-Site Scripting Vulnerabilities. CVE-2007-4475CVE-53066 . remote exploit for Windows platform

Trust: 0.6

sources: EXPLOIT-DB: 32879

AFFECTED PRODUCTS

vendor:sapmodel:maxdbscope:eqversion:7.4/7.6

Trust: 1.6

vendor:sapmodel:ag sapgui eai webviewer3dscope: - version: -

Trust: 0.5

vendor:sapmodel:ag sapgui patch levelscope:eqversion:7.108

Trust: 0.3

vendor:sapmodel:ag sapgui patch levelscope:neversion:7.109

Trust: 0.3

vendor:sapmodel:maxdb buildscope:eqversion:7.6.3007

Trust: 0.3

vendor:sapmodel:maxdbscope:eqversion:7.6.03.15

Trust: 0.3

vendor:sapmodel:maxdbscope:eqversion:7.6.00.37

Trust: 0.3

vendor:sapmodel:maxdbscope:eqversion:7.6.0.37

Trust: 0.3

vendor:sapmodel:maxdbscope:eqversion:7.4.3.32

Trust: 0.3

sources: BID: 34310 // BID: 34319 // PACKETSTORM: 82972 // EXPLOIT-DB: 32879 // EDBNET: 54386

EXPLOIT

source: https://www.securityfocus.com/bid/34319/info

SAP MaxDB is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

http://example.com:9999/webdbm?Event=DBM_LOGON&Action=VIEW&Server=&Database=[XSS]
http://example.com:9999/webdbm?Event=DBM_LOGON&Action=VIEW&Server=&User=[XSS]
http://example.com:9999/webdbm?Event=DBM_LOGON&Action=VIEW&Server=&Database=&User=&Password=[XSS]

Trust: 1.0

sources: EXPLOIT-DB: 32879

EXPLOIT LANGUAGE

html

Trust: 0.6

sources: EXPLOIT-DB: 32879

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 32879

TYPE

'webdbm' Multiple Cross-Site Scripting Vulnerabilities

Trust: 1.6

sources: EXPLOIT-DB: 32879 // EDBNET: 54386

TAGS

tag:exploit

Trust: 0.5

tag:overflow

Trust: 0.5

tag:arbitrary

Trust: 0.5

tag:activex

Trust: 0.5

sources: PACKETSTORM: 82972

CREDITS

Digital Security Research Group

Trust: 0.6

sources: EXPLOIT-DB: 32879

EXTERNAL IDS

db:NVDid:CVE-2007-4475

Trust: 2.4

db:BIDid:34319

Trust: 1.9

db:EXPLOIT-DBid:32879

Trust: 1.6

db:EDBNETid:54386

Trust: 0.6

db:PACKETSTORMid:82972

Trust: 0.5

db:CERT/CCid:VU#985449

Trust: 0.3

db:BIDid:34310

Trust: 0.3

sources: BID: 34310 // BID: 34319 // PACKETSTORM: 82972 // EXPLOIT-DB: 32879 // EDBNET: 54386

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2007-4475

Trust: 2.1

url:https://www.securityfocus.com/bid/34319/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/32879/

Trust: 0.6

url:http://www.kb.cert.org/vuls/id/985449

Trust: 0.3

url:https://service.sap.com/sap/support/notes/1153794

Trust: 0.3

url:http://support.microsoft.com/kb/240797

Trust: 0.3

url:http://www.sap.com

Trust: 0.3

url:https://www.sdn.sap.com/irj/sdn/maxdb

Trust: 0.3

sources: BID: 34310 // BID: 34319 // PACKETSTORM: 82972 // EXPLOIT-DB: 32879 // EDBNET: 54386

SOURCES

db:BIDid:34310
db:BIDid:34319
db:PACKETSTORMid:82972
db:EXPLOIT-DBid:32879
db:EDBNETid:54386

LAST UPDATE DATE

2022-07-27T09:19:55.155000+00:00


SOURCES UPDATE DATE

db:BIDid:34310date:2010-03-09T06:02:00
db:BIDid:34319date:2009-03-31T21:16:00

SOURCES RELEASE DATE

db:BIDid:34310date:2009-03-31T00:00:00
db:BIDid:34319date:2009-03-31T00:00:00
db:PACKETSTORMid:82972date:2009-11-26T00:34:53
db:EXPLOIT-DBid:32879date:2009-03-31T00:00:00
db:EDBNETid:54386date:2009-03-31T00:00:00