.. / CVE-2018-19386

Exploit for SolarWinds Database Performance Analyzer 11.1.457 - Cross-Site Scripting (CVE-2018-19386)

Description:

SolarWinds Database Performance Analyzer 11.1.457 contains a reflected cross-site scripting vulnerability in its idcStateError component, where the page parameter is reflected into the HREF of the ‘Try Again’ Button on the page, aka a /iwc/idcStateError.iwc?page= URI.

Nuclei Template

View the template here CVE-2018-19386.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-19386.yaml
Copy

References:

https://github.com/Elsfa7-110/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2018-19386
https://i.imgur.com/Y7t2AD6.png
https://github.com/merlinepedra/nuclei-templates
https://medium.com/greenwolf-security/reflected-xss-in-solarwinds-database-performance-analyzer-988bd7a5cd5