Tuesday, 23 June 2015

Found XSS vulnerability in Manage Engine Asset Explorer v6.1.

ManageEngine Asset Explorer v6.1 - XSS Vulnerability



Product & Service Introduction (Taken from their homepage):
ManageEngine AssetExplorer is a web-based IT Asset Management (ITAM) software that helps you monitor and manage assets in your network from Planning phase to Disposal phase. AssetExplorer provides you with a number of ways to ensure discovery of all the assets in your network. You can manage software & hardware assets, ensure software license compliance and track purchase orders & contracts - the whole nine yards! AssetExplorer is very easy to install and works right out of the box.
(Homepage: https://www.manageengine.com/products/asset-explorer/ )

Abstract Advisory Information:
Cross site scripting attack can be performed on the manage engine asset explorer. If the 'publisher' name contains vulnerable script, it gets executed in the browser.

Affected Products:
Manage Engine
Product: Asset Explorer - Web Application 6.1.0 (Build 6112)

Severity Level:

Technical Details & Description:
  1. Add a vendor with a script in it to the registry.
  2. Login to the product.
  3. Scan the endpoint where the registry is modified.
  4. In the right pane, go to software->Scanned Software
  5. The script gets executed.
Vulnerable Product(s):
Manage Engine Asset Explorer

Affected Version(s):
Version 6.1.0 / Build Number 6112
(Earlier versions i did not test)

Vulnerability Type(s):
Persistent Cross Site Scripting

Add the following registry entry in the machine, for targeted attack.

Windows Registry Editor Version 5.00
"DisplayName"="A fake software 2 installed"
"UninstallString"="C:\\Program Files\\fake\\uninst.exe"
"Publisher"="<script> alert(\"XSS\"); </script>"

Security Risk:

Credits & Authors:
Suraj Krishnaswami (suraj.krishnaswami@gmail.com)

Discovered at Wed, March 3, 2015
Informed manage engine about the vulnerability: March 4, 2015
Case moved to development team: March 4, 2015
Asked for updates: March 9, 2015
Asked for updates: March 13, 2015
Asked for updates: April 14, 2015
Public Disclosure at Mon, June 22, 2015


  1. I praise your hard work that is making this blog informative in the License Management Software.
    Thanks for sharing a valuable blog.
    Licence Management Software

  2. This comment has been removed by a blog administrator.

  3. Your genius men! This document will explain you about the Vulnerability, which allows remote attackers to inject client-side script into Desktop Central's web page.

    Kim of S.I. Unik

  4. Thanks for the valuable feedback. I think that strategy is sound and can be easily replicable.Great posts. I love this article. KONA’s Change Management specialists employ a world-class methodology for effectively managing change and fully realizing the intended benefits.

  5. Your blog is very useful post shar thanks for sharing .asset management software

  6. Compliance Management Software-Contact us for various kinds of system management software like compliance management, Equipment Rental Management, equipment inventory management software etc.

  7. LexCare is a specialized company in providing Legal compliance software in India. We have created comprehensive repository of compliances under all (Central/State) Indian.

  8. I definitely appreciate your blog. Excellent work!
    law firm software

  9. Thanks for the post you shared. Good to see it..!! Thanks mate..
    Database for grantmakers

  10. We take the frustration out of parking management for Apartments, Home Owners Associations, Condominiums, Townhouses Co-ops, and other parking areas.Webparkingsoftware.com has reinvented how parking management should be done.

    Parking Management Software
    online parking software
    Cloud based parking solutions

  11. Your blog is absolutely fantastic. Lots of great information and inspiration, both of which we all need. Web design is significant in making the best website. Thanks

    web design austin
    web developer austin


  12. It is mandatory for you to take entire control of your business, and it can only be done with the help of this
    Hardware Inventory Management

  13. Hi Suraj, thanks for this post describing the specs of AssetExplorer. I'm sure this will help many. Best Asset Management Software can help people who looking for a similar asset management software. You can find and compare the most appropriate software for your business.

  14. This comment has been removed by a blog administrator.

  15. I think this article will fully complement you. Please continue publishing helpful topics like this. Regards, from Asset Management Software

    Asset Tracking Software

    Property Maintenance Software

  16. I’m not sure where you’re getting your information, but good topic. I need to spend some time learning more or understanding more. Thanks for fantastic info I was looking for this information for my mission.
    Asset Management Software
    Asset Tracking Software
    Asset Management Software India
    Asset Management Software Chennai

  17. Thanks for provide great informatic and looking beautiful blog, really nice required information & the things i never imagined and i would request, wright more blog and blog post like that for us. Thanks you once agian

    special marriage act
    name add in birth certificate
    passport agent
    court marriage in delhi
    name change
    marriage registration
    birth certificate in gurgaon
    birth certificate in noida
    birth certificate in ghaziabad
    birth certificate in delhi

  18. Is your Gemini account not confirmed at this point and you need check technique? On the off chance that you don't have the foggiest idea how to manage blunders, you can search for the help. Simply dial Gemini contact number and get moment and plain-cruising cures from the bundle of experts whose point is to delete every one of your mistakes so you can give your complete consideration on exchanging as opposed to agonizing over the specialized issues. You can connect with the administrators by dialing our toll free number.


  19. Buy Vyvanse Online
    Buy Oxycodone online

    Buy Oxycontin online
    Buy suboxone online

    Buy Macaw Parrots Online
    Macaw Parrots For Sale

    Welcome to Official Macaw Parrots For Sale Farm. After talking to breeders and vet and trying to get experience with birds in real life are both good, just note that a vet is going to give you waaay more unbiased info while you will need to be on your guard for a breeder just trying to make a sale. Like pet stores, some will not hesitate to up-sell all of the fantastic qualities of their little baby macaw, showing you how cuddly it is, how quiet, and not mentioning how puberty will most likely completely change their personalities. Macaw Parrots for Sale.

    Macaws For Sale
    Macaw parrots farm

    Buy Marijuana Online
    Weed For Sale

    Cannabis, also known as marijuana among other names, is a psychoactive drug from the Cannabis plant used for medical or recreational purposes. The main psychoactive part of cannabis is tetrahydrocannabinol, one of the 483 known compounds in the plant, including at least 65 other cannabinoid

    Mail Order Marijuana
    Order weed Online USA

    Goldendoodle Puppies For Sale
    Adopt a Golden Doodle Puppy

    The Goldendoodle is a cross-breed dog, obtained by breeding a Golden Retriever with a Poodle. The name, which alters "poodle" to "doodle" by analogy to "Labradoodle", another poodle cross, was coined in 1992.

    Golden Doodle Pupies for sale near me
    Golden doodle Puppies USA

    Tavor 7 For Sale
    Buy Tavor Online

    Tavor 7 For Sale. The TAVOR 7 is a fully ambidextrous platform on which the ejection side and the charging handle can be switched quickly and easily from side ...

    Firearms For sale
    Tavor 7 for sale USA

    Buy Dank Vapes Carts Full Gram
    Dank Vapes for sale
    Dank Vapes
    Dank Carts for sale online

    Buy Space Monkey Meds Online
    Buy Weed Tins Online

     Buy Space Monkey Meds Online - Buy Weed Tins Online Our weed tins stands unique in quality and purity. Our mail order marijuana services stand apart in stealth and discretion. Place an order to buy weed tins online with us today and benefit from our amazing prices and coupon codes. Ordering space monkey meds for sale online can be a challenging task to newbies. Here at Weed tins Shop, we provide weed tins for sale with easy purchasing and checkout procedures.

    Buy Runtz Strain Online
    Runtz OG

  20. Hello do you know that the best treatment for opiod addiction,illegal or prescription is suboxone pills. Suboxone pills provides versatility in the way it helps patients.our medicated shop is the place to shop for all kinds of medication needs including;
    Check out all our available pills on our online shop. https://greenlandspharmacy.com/

  21. Dank Vapes Full Cartridges. (Dank vapes) is a brand that just makes packaging, they sell their packaging to farms. how would a package brand make anymoney?How the fuck is everyone all the sudden selling these? (From what I’ve seen) the first set of these i got were so legit. The 4th/5th time around not so much.The ones circulating around now give side effects like headaches, blacking out thinking i was tired, hallucinations & nausea. The first carts were made for the purpose to be good carts. The more the demand for the carts the farms were able to produce shittier oil from weed that can’t be sold in clubs Because it can’t pass a test

    stiiizy pods flavors

    Dank vapes cartridges

    buy stiiizy pods

    dank vapes official

    dank vape

    dank vapes

    dank vapes

    dank vape flavors

    dank vape carts

    dank vapes fruity pebbles

    dank vapes official account

    buy smart carts

    dank vapes

    vape dank

    dank vapes

    exotic carts

    exotic carts flavors

    mario carts

  22. Do you know cali420supplies is the best marijuana dispensary in california and do ship to all states and 3 days of discreet shipping.
    click to the links below and get high we have the best quality(TOP SHELF).
    EMAIL US AT:dovianlawson@gmail.com
    we also give free offers for bulk orders