CVE-2018-1408
published 2018-07-10CVE-2018-1408: IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.66%
47.3th percentile
IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138446.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | — | — |
| ibm | rational_team_concert | 5.0 – 5.0.2 | — |
| ibm | rational_team_concert | 6.0 – 6.0.5 | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
exploitdb·2018-12-04·CVSS 8.1
CVE-2018-19616 [HIGH] Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
---
# Exploit Title: Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control
# Date: 2018-11-27
# Exploit Author: Luca.Chiou
# Vendor Homepage: https://www.rockwellautomation.com/
# Version: 1408-EM3A-ENT B
# Tested on: It is a proprietary devices: https://ab.rockwellautomation.com/zh/Energy-Monitoring/1408-PowerMonitor-1000
# CVE : CVE-2018-19616
# 1. Description:
# In Rockwell Automation Allen-Bradley PowerMonitor 1000 web page, there are a few buttons are disabled,
# such as “Edit”, “Remove”, “AddNew”, “Change Policy Holder” and “Security Configuration”.
# View the source code of login page, those buttons/functions just use the “disabled” parameter to control th
Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
exploitdb·2018-12-03
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
---
# Exploit Title: Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
# Date: 2018-11-27
# Exploit Author: Luca.Chiou
# Vendor Homepage: https://www.rockwellautomation.com/
# Version: 1408-EM3A-ENT B
# Tested on: It is a proprietary devices: https://ab.rockwellautomation.com/zh/Energy-Monitoring/1408-PowerMonitor-1000
# CVE : N/A
# 1. Description:
# In Rockwell Automation Allen-Bradley PowerMonitor 1000 web page,
# user can add a new user by access the /Security/Security.shtm.
# When users add a new user, the new user’s account will in the post data.
# Attackers can inject malicious XSS code in user’s account parameter of post data.
# The user’s account parameter will be stored in databa
Exploit-DB
LibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File Disclosure
exploitdb·2018-02-10·CVSS 9.8
CVE-2018-6871 [CRITICAL] LibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File Disclosure
LibreOffice
Proof-of-concept: send private keys (this cells of course must be moved and set color to white)
Current user:
#VALUE!
689
676
#VALUE!
(change this)Address:
http://localhost:8080
List of private keys:
#VALUE!
Send:
0 (default path)
#VALUE!
1
132
109
96
#VALUE!
2
297
259
246
#VALUE!
3
436
409
396
#VALUE!
4
586
563
550
#VALUE!
5
718
695
682
#VALUE!
6
882
860
847
#VALUE!
7
1267
1240
1227
#VALUE!
8
1408
1383
1370
#VALUE!
9
#VALUE!
#VALUE!
#VALUE!
#VALUE!
```
2018-07-10
Published