<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nGenuity Information Services &#187; zenoss</title>
	<atom:link href="http://www.ngenuity.org/wordpress/tag/zenoss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ngenuity.org/wordpress</link>
	<description>Security for the A.D.D generation</description>
	<lastBuildDate>Wed, 10 Mar 2010 19:25:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>NGENUITY-2010-001 Zenoss getJSONEventsInfo SQL Injection</title>
		<link>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/</link>
		<comments>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 08:55:57 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[sqli]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[zenoss]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=206</guid>
		<description><![CDATA[nGenuity Information Services &#8211; Security Advisory
   Advisory ID: NGENUITY-2010-001 - Zenoss getJSONEventsInfo SQL Injection
   Application: Zenoss 2.3.3
        Vendor: Zenoss
Vendor website: http://www.zenoss.com
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)
           BID: 37802

  I. BACKGROUND
    [...]]]></description>
			<content:encoded><![CDATA[<p>nGenuity Information Services &#8211; Security Advisory</p>
<pre>   Advisory ID: NGENUITY-2010-001 - Zenoss getJSONEventsInfo SQL Injection
   Application: Zenoss 2.3.3
        Vendor: Zenoss
Vendor website: <a title="Zenoss" href="http://www.zenoss.com" target="_blank">http://www.zenoss.com</a>
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)
           BID: <a href="http://www.securityfocus.com/bid/37802/exploit">37802</a>

  I. BACKGROUND
     "Zenoss Core is an award-winning open source IT monitoring product that
     effectively manages the configuration, health and performance of
     networks, servers and applications through a single, integrated
     software package." [1] 

II. DETAILS
    getJSONEventsInfo contains multiple SQL Injection vulnerabilities due to improperly
    sanitized user provided input. The following URL parameters are injectable: severity,
    state, filter, offset, and count.

    Authentication as an admin or regular user is required for successful exploitation.
    Depending on the type of attack, it may also be accomplished via Cross-Site Request
    Forgery (CSRF).

    A proof of concept request might look like this
      /zport/dmd/Events/getJSONEventsInfo?severity=1&amp;state=1&amp;filter=&amp;
      offset=0&amp;count=60 into outfile "/tmp/z"</pre>
<pre>III. REFERENCES
     [1] - http://www.zenoss.com

 IV. VENDOR COMMUNICATION
     3.10.2009 - Vulnerability Discovery
     8.21.2009 - Requested status from vendor
     9.29.2009 - Vendor call (Fix pending)

     Update 1.21.2010
     This vulnerability was fixed prior to version 2.5.

http://dev.zenoss.org/trac/changeset/15257

Copyright (c) 2009 nGenuity Information Services, LLC</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
