Apple Mac OS X Weblog Server Cross-Site Scripting Vulnerabilities
BID:14569
Info
Apple Mac OS X Weblog Server Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 14569 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2523 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery credited to Donnie Werner <[email protected]> and Atsushi MATSUO. |
| Vulnerable: |
Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X Weblog Server Cross-Site Scripting Vulnerabilities
Apple Mac OS X Weblog Server is prone to cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
This issue was originally described in BID 14567 Apple Mac OS X Multiple Vulnerabilities. It is now being assigned its own BID.
Apple Mac OS X Weblog Server is prone to cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
This issue was originally described in BID 14567 Apple Mac OS X Multiple Vulnerabilities. It is now being assigned its own BID.
Exploit / POC
Apple Mac OS X Weblog Server Cross-Site Scripting Vulnerabilities
No exploit code is required. The following proof of concept URI's were provided:
input malicious script into author and comment sections in
the comment option on the weblog.
eg:<SCRIPT>alert(document.cookie);</SCRIPT> [cookie theft]
eg:<iframe src="http://somesite.com"></iframe> [redirect]
http://www.example.com:16080/weblog/[bloguser]/?permalink=[blogentry]&comment=y&page=comments&category=%2F&author=[script]&authorEmail=&authorURL=&commentText=[script]&submit=Submit+Comment
No exploit code is required. The following proof of concept URI's were provided:
input malicious script into author and comment sections in
the comment option on the weblog.
eg:<SCRIPT>alert(document.cookie);</SCRIPT> [cookie theft]
eg:<iframe src="http://somesite.com"></iframe> [redirect]
http://www.example.com:16080/weblog/[bloguser]/?permalink=[blogentry]&comment=y&page=comments&category=%2F&author=[script]&authorEmail=&authorURL=&commentText=[script]&submit=Submit+Comment
Solution / Fix
Apple Mac OS X Weblog Server Cross-Site Scripting Vulnerabilities
Solution:
Apple has released fixes:
Apple Mac OS X 10.4.2
Apple Mac OS X Server 10.4.2
Solution:
Apple has released fixes:
Apple Mac OS X 10.4.2
-
Apple SecUpd2005-007Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07794&plat form=osx&method=sa/SecUpd2005-007Ti.dmg
Apple Mac OS X Server 10.4.2
-
Apple SecUpdSrvr2005-007Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=07795&plat form=osx&method=sa/SecUpdSrvr2005-007Ti.dmg
References
Apple Mac OS X Weblog Server Cross-Site Scripting Vulnerabilities
References:
References: