nCircle patches PureCloud vulnerability scanner on Vulnerability-Lab report
Jan 29, 2013
    The Vulnerability-Laboratory  Research Team discovered  persistent and client side POST Injection web vulnerability in the nCircle PureCloud (cloud-based) Vulnerability Scanner  Application.     The vulnerability allows an attacker to inject own malicious script code in the vulnerable module on application side.        Benjamin K.M. from Vulnerability-Laboratory provide more technical details about these flaws, the first vulnerability is located in the Scan Now > Scan Type > Perimeter Scan > Scan section when processing to request via the ` Scan Specific Devices - [Add Devices] ` module and the bound vulnerable formErrorContent exception-handling application parameters.     The persistent injected script code will be executed out of the `invalid networks` web application exception-handling. To bypass the standard validation of the application filter the attacker need to provoke the specific invalid networks exception-handling error.     In the second ste...