BEA WebLogic Server And WebLogic Express Administration Console Cross-Site Scripting Vulnerability
BID:13400
Info
BEA WebLogic Server And WebLogic Express Administration Console Cross-Site Scripting Vulnerability
| Bugtraq ID: | 13400 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1380 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2005 12:00AM |
| Updated: | Jul 12 2009 02:06PM |
| Credit: | Discovery of this issue is credited to Alexander Kornbrust. |
| Vulnerable: |
Horde Project Chora 1.2.2 Horde Project Chora 1.2.1 Horde Project Chora 1.2 Horde Project Chora 1.1 BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 8.1 SP 3 BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 8.1 SP 3 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 |
| Not Vulnerable: |
Horde Project Chora 1.2.3 |
Discussion
BEA WebLogic Server And WebLogic Express Administration Console Cross-Site Scripting Vulnerability
A remote cross-site scripting vulnerability affects BEA WebLogic Server and WebLogic Express administration console. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
A remote cross-site scripting vulnerability affects BEA WebLogic Server and WebLogic Express administration console. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
BEA WebLogic Server And WebLogic Express Administration Console Cross-Site Scripting Vulnerability
No exploit is required to leverage this issue. The following example is available:
http://example.com:8001/console/actions/jndi/JndiFramesetAction?server='<script>alert(document.cookie);</script>mydomain%3AName%3Dmyserver%2CType%3DS
No exploit is required to leverage this issue. The following example is available:
http://example.com:8001/console/actions/jndi/JndiFramesetAction?server='<script>alert(document.cookie);</script>mydomain%3AName%3Dmyserver%2CType%3DS
Solution / Fix
BEA WebLogic Server And WebLogic Express Administration Console Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Horde Project Chora 1.1
Horde Project Chora 1.2
Horde Project Chora 1.2.1
Horde Project Chora 1.2.2
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Horde Project Chora 1.1
-
Horde Chora 1.2.3
http://www.horde.org/chora/download/
Horde Project Chora 1.2
-
Horde Chora 1.2.3
http://www.horde.org/chora/download/
Horde Project Chora 1.2.1
-
Horde Chora 1.2.3
http://www.horde.org/chora/download/
Horde Project Chora 1.2.2
-
Horde Chora 1.2.3
http://www.horde.org/chora/download/
References
BEA WebLogic Server And WebLogic Express Administration Console Cross-Site Scripting Vulnerability
References:
References:
- Chora Homepage (Horde Project)
- Pandora Homepage (Pandora FMS Team)
- Weblogic (BEA Systems)
- Cross Site Scripting in BEA Admin Console (Alexander Kornbrust
)