Matt Posted July 12, 2013 Report Posted July 12, 2013 Description : BMC Service Desk Express (SDE) version 10.2.1.95 suffers from cross site scripting and remote SQL injection vulnerabilities.Author : Nuri FattahSource : BMC Service Desk Express 10.2.1.95 XSS / SQL Injection ? Packet StormCode : Classification: NON SENSITIVE INFORMATION RELEASABLE TO THE PUBLICMultiple vulnerabilities in BMC SERVICE DESK EXPRESS (SDE) Version10.2.1.95Affected Product:BMC SERVICE DESK EXPRESS (SDE) Version 10.2.1.95Timeline:07 June 2013 - Vulnerability found12 June 2013 - Vendor informed17 June 2013 - Vendor replied/confirmed & opened service ticketCredits:Nuri Fattah of NATO / NCIRC (www.ncirc.nato.int)CVE: To be assignedNCIRC ID: NCIRC-2013127-02Description:Multiple vulnerabilities, including Cross-Site Scripting(XSS) and SQLinjection were identified in the latest version of BMC SERVICE DESKEXPRESSVulnerability Details:1. SQL injectiona. /SDE/DashBoardGUI.aspx vuln parameter: [ASPSESSIONIDASSRATTQ cookie]b. /SDE/DashBoardGUI.aspx vuln parameter: [TABLE_WIDGET_1 cookie]c. /SDE/DashBoardGUI.aspx vuln parameter: [TABLE_WIDGET_2 cookie]d. SDE/DashBoardGUI.aspx vuln parameter: [browserDateTimeInfo cookie]e. /SDE/DashBoardGUI.aspx vuln parameter: [browserNumberInfo cookie]f. /SDE/login.aspx vuln parameter: [UID]2. Reflected XSSa. /SDE/QV_admin.aspx vuln parameter: [SelTab]b. /SDE/QV_grid.aspx vuln parameter: [CallBack]c. /SDE/commonhelp.aspx vuln parameter: [HelpPage]example:GET/SDE/QV_grid.aspx?QuerySeq=1068&CondVal=1%40V1%40ADMINISTRATION%401&CallBack=parent.parent.frames.TmInputs.callBack(doGridDataCallBack.arguments[0]);</script><script>alert(99817)</script>&ViewType=g&bRefresh=HTTP/1.1Solution:No Solution has yet been provided.Please contact the vendor. Quote