Microsoft Windows DHTML Edit Control Script Injection Vulnerability
BID:11950
Info
Microsoft Windows DHTML Edit Control Script Injection Vulnerability
| Bugtraq ID: | 11950 |
| Class: | Design Error |
| CVE: |
CVE-2004-1319 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery is credited to Paul <[email protected]>. |
| Vulnerable: |
Nortel Networks Optivity Telephony Manager (OTM) Nortel Networks Mobile Voice Client 2050 Nortel Networks IP softphone 2050 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows DHTML Edit Control Script Injection Vulnerability
Microsoft Windows DHTML Edit control may be used to carry out cross-domain script injection through Internet Explorer. This issue may allow an attacker to execute malicious script code in a user's browser to facilitate cross-site scripting attacks.
An attacker may be able to steal cookie-based authentication credentials through this vulnerability. Other attacks may be possible as well.
Note: This issue was originally documented as an Internet Explorer vulnerability. Microsoft has reported that this vulnerability is an operating system issue and has released appropriate operating system fixes.
Microsoft Windows DHTML Edit control may be used to carry out cross-domain script injection through Internet Explorer. This issue may allow an attacker to execute malicious script code in a user's browser to facilitate cross-site scripting attacks.
An attacker may be able to steal cookie-based authentication credentials through this vulnerability. Other attacks may be possible as well.
Note: This issue was originally documented as an Internet Explorer vulnerability. Microsoft has reported that this vulnerability is an operating system issue and has released appropriate operating system fixes.
Exploit / POC
Microsoft Windows DHTML Edit Control Script Injection Vulnerability
A proof of concept is available from the following location:
http://freehost07.websamba.com/greyhats/abusiveparent.htm
A proof of concept is available from the following location:
http://freehost07.websamba.com/greyhats/abusiveparent.htm
Solution / Fix
Microsoft Windows DHTML Edit Control Script Injection Vulnerability
Solution:
Microsoft has released updates for supported platforms. Windows 98/98SE/ME updates may be obtained through Windows Update.
Nortel Networks has released security advisory 2005005513-2 acknowledging this issue. Please the referenced advisory for further information.
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Professional SP3
Microsoft Windows XP Tablet PC Edition SP1
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows XP Home SP2
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows XP Media Center Edition SP1
Microsoft Windows Server 2003 Web Edition
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home SP1
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows XP Professional SP2
Microsoft Windows 2000 Professional SP4
Microsoft Windows XP Professional SP1
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Solution:
Microsoft has released updates for supported platforms. Windows 98/98SE/ME updates may be obtained through Windows Update.
Nortel Networks has released security advisory 2005005513-2 acknowledging this issue. Please the referenced advisory for further information.
Microsoft Windows XP Media Center Edition SP2
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows XP 64-bit Edition SP1
-
Microsoft Security Update for Windows XP 64-bit Edition (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9E0247B8-240E -416C-9586-ACD5EF8578DE&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=AEA07CBA-0E2B -4A22-91ED-1D23BB012C04&displaylang=en
Microsoft Windows 2000 Professional SP3
-
Microsoft Security Update for Windows 2000 (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=AEA07CBA-0E2B -4A22-91ED-1D23BB012C04&displaylang=en
Microsoft Windows XP Tablet PC Edition SP1
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft Security Update for Windows Server 2003 (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=E99F5BDD-8EA8 -4837-960E-0D20DEA9AC4D&displaylang=en
Microsoft Windows XP Home SP2
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows XP Tablet PC Edition SP2
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows XP Media Center Edition SP1
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows Server 2003 Web Edition
-
Microsoft Security Update for Windows Server 2003 (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=E99F5BDD-8EA8 -4837-960E-0D20DEA9AC4D&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=AEA07CBA-0E2B -4A22-91ED-1D23BB012C04&displaylang=en
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft !!DHTMLEditControl Microsoft Windows Server 2003 64-bit
-
Microsoft Security Update for Windows Server 2003 64-bit Edition and Windows XP 64-bit Edition, Version 2003 (
http://www.microsoft.com/downloads/details.aspx?familyid=2CE98263-2AB4 -4FE3-8B0B-5B3155119730&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=E99F5BDD-8EA8 -4837-960E-0D20DEA9AC4D&displaylang=en
Microsoft Windows XP 64-bit Edition Version 2003
-
Microsoft Security Update for Windows Server 2003 64-bit Edition and Windows XP 64-bit Edition, Version 2003 (
http://www.microsoft.com/downloads/details.aspx?familyid=2CE98263-2AB4 -4FE3-8B0B-5B3155119730&displaylang=en
Microsoft Windows XP Professional SP2
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=AEA07CBA-0E2B -4A22-91ED-1D23BB012C04&displaylang=en
Microsoft Windows XP Professional SP1
-
Microsoft Security Update for Windows XP (KB891781)
http://www.microsoft.com/downloads/details.aspx?familyid=9490E7D2-03C2 -463A-B3D0-B949F5295208&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Edition and Windows XP 64-bit Edition, Version 2003 (
http://www.microsoft.com/downloads/details.aspx?familyid=2CE98263-2AB4 -4FE3-8B0B-5B3155119730&displaylang=en
References
Microsoft Windows DHTML Edit Control Script Injection Vulnerability
References:
References: