Apache Struts Error Response Cross-Site Scripting Vulnerability
BID:15512
Info
Apache Struts Error Response Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15512 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3745 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2005 12:00AM |
| Updated: | Jan 02 2007 07:26PM |
| Credit: | Irene Abezgauz is credited with the discovery of this vulnerability. |
| Vulnerable: |
Apache Struts 1.2.7 |
| Not Vulnerable: |
ScriptSolutions PerlDiver 2.32 Apache Struts 1.2.8 |
Discussion
Apache Struts Error Response Cross-Site Scripting Vulnerability
Struts is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Struts is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Apache Struts Error Response Cross-Site Scripting Vulnerability
No exploit is required.
The following proof-of-concept URI is available:
http://www.example.com/struts-virtdir/<script>alert('test')</script>.do
No exploit is required.
The following proof-of-concept URI is available:
http://www.example.com/struts-virtdir/<script>alert('test')</script>.do
Solution / Fix
Apache Struts Error Response Cross-Site Scripting Vulnerability
Solution:
Red Hat has released advisory RHSA-2006:0157-01 along with fixes to address this issue for Red Hat Application Server 3. Please see the referenced advisory for more information.
The vendor has addressed this issue in version 1.2.8:
Apache Struts 1.2.7
Solution:
Red Hat has released advisory RHSA-2006:0157-01 along with fixes to address this issue for Red Hat Application Server 3. Please see the referenced advisory for more information.
The vendor has addressed this issue in version 1.2.8:
Apache Struts 1.2.7
-
Apache Software Foundation struts-1.2.8-src.tar.gz
http://struts.apache.org/download.cgi -
RedHat jakarta-commons-validator-1.1.4-1jpp_2rh.noarch.rpm
Red Hat Application Server 3AS:
ftp://updates.redhat.com/enterprise/3AS/en/RHAPS/SRPMS/jakarta-commons -validator-1.1.4-1jpp_2rh.noarch.rpm -
RedHat jakarta-commons-validator-1.1.4-1jpp_2rh.noarch.rpm
Red Hat Application Server 3ES:
ftp://updates.redhat.com/enterprise/3ES/en/RHAPS/SRPMS/jakarta-commons -validator-1.1.4-1jpp_2rh.noarch.rpm -
RedHat jakarta-commons-validator-1.1.4-1jpp_2rh.noarch.rpm
Red Hat Application Server 3WS:
ftp://updates.redhat.com/enterprise/3WS/en/RHAPS/SRPMS/jakarta-commons -validator-1.1.4-1jpp_2rh.noarch.rpm -
RedHat jakarta-commons-validator-javadoc-1.1.4-1jpp_2rh.noarch.rpm
Red Hat Application Server 3AS:
ftp://updates.redhat.com/enterprise/3AS/en/RHAPS/SRPMS/jakarta-commons -validator-javadoc-1.1.4-1jpp_2rh.noarch.rpm -
RedHat jakarta-commons-validator-javadoc-1.1.4-1jpp_2rh.noarch.rpm
Red Hat Application Server 3ES:
ftp://updates.redhat.com/enterprise/3ES/en/RHAPS/SRPMS/jakarta-commons -validator-javadoc-1.1.4-1jpp_2rh.noarch.rpm -
RedHat jakarta-commons-validator-javadoc-1.1.4-1jpp_2rh.noarch.rpm
Red Hat Application Server 3WS:
ftp://updates.redhat.com/enterprise/3WS/en/RHAPS/SRPMS/jakarta-commons -validator-javadoc-1.1.4-1jpp_2rh.noarch.rpm -
RedHat struts-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3AS:
ftp://updates.redhat.com/enterprise/3AS/en/RHAPS/SRPMS/struts-1.2.8-1j pp_2rh.noarch.rpm -
RedHat struts-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3ES:
ftp://updates.redhat.com/enterprise/3ES/en/RHAPS/SRPMS/struts-1.2.8-1j pp_2rh.noarch.rpm -
RedHat struts-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3WS:
ftp://updates.redhat.com/enterprise/3WS/en/RHAPS/SRPMS/struts-1.2.8-1j pp_2rh.noarch.rpm -
RedHat struts-javadoc-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3AS:
ftp://updates.redhat.com/enterprise/3AS/en/RHAPS/SRPMS/struts-javadoc- 1.2.8-1jpp_2rh.noarch.rpm -
RedHat struts-javadoc-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3ES:
ftp://updates.redhat.com/enterprise/3ES/en/RHAPS/SRPMS/struts-javadoc- 1.2.8-1jpp_2rh.noarch.rpm -
RedHat struts-javadoc-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3WS:
ftp://updates.redhat.com/enterprise/3WS/en/RHAPS/SRPMS/struts-javadoc- 1.2.8-1jpp_2rh.noarch.rpm -
RedHat struts-manual-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3AS:
ftp://updates.redhat.com/enterprise/3AS/en/RHAPS/SRPMS/struts-manual-1 .2.8-1jpp_2rh.noarch.rpm -
RedHat struts-manual-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3ES:
ftp://updates.redhat.com/enterprise/3ES/en/RHAPS/SRPMS/struts-manual-1 .2.8-1jpp_2rh.noarch.rpm -
RedHat struts-manual-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3WS:
ftp://updates.redhat.com/enterprise/3WS/en/RHAPS/SRPMS/struts-manual-1 .2.8-1jpp_2rh.noarch.rpm -
RedHat struts-webapps-tomcat5-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3AS:
ftp://updates.redhat.com/enterprise/3AS/en/RHAPS/SRPMS/struts-webapps- tomcat5-1.2.8-1jpp_2rh.noarch.rpm -
RedHat struts-webapps-tomcat5-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3ES:
ftp://updates.redhat.com/enterprise/3ES/en/RHAPS/SRPMS/struts-webapps- tomcat5-1.2.8-1jpp_2rh.noarch.rpm -
RedHat struts-webapps-tomcat5-1.2.8-1jpp_2rh.noarch.rpm
Red Hat Application Server 3WS:
ftp://updates.redhat.com/enterprise/3WS/en/RHAPS/SRPMS/struts-webapps- tomcat5-1.2.8-1jpp_2rh.noarch.rpm
References
Apache Struts Error Response Cross-Site Scripting Vulnerability
References:
References:
- Security Advisory: Struts Error Message Cross Site Scripting (Hacktics)
- Struts Homepage (Apache Software Foundation)