Microsoft Content Management Server Cross-Site Scripting Vulnerability
BID:22860
Info
Microsoft Content Management Server Cross-Site Scripting Vulnerability
| Bugtraq ID: | 22860 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0939 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2007 12:00AM |
| Updated: | Jun 13 2007 08:29PM |
| Credit: | Martyn Tovey of Netcraft is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Content Management Server 2002 SP2 Microsoft Content Management Server 2002 SP1 Microsoft Content Management Server 2002 Microsoft Content Management Server 2001 SP1 Microsoft Content Management Server 2001 HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Content Management Server Cross-Site Scripting Vulnerability
Microsoft Content Management Server (MCMS) is prone to an unspecified cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials, spoof content, or perform actions on behalf of the victim user; this could aid in further attacks.
Microsoft Content Management Server (MCMS) is prone to an unspecified cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials, spoof content, or perform actions on behalf of the victim user; this could aid in further attacks.
Exploit / POC
Microsoft Content Management Server Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Microsoft Content Management Server Cross-Site Scripting Vulnerability
Solution:
Microsoft has released an advisory to address this issue in supported versions of affected applications.
HP Storage Management Appliance is affected by the issue; please see the referenced HP advisory.
Microsoft Content Management Server 2001 SP1
Microsoft Content Management Server 2002 SP2
Solution:
Microsoft has released an advisory to address this issue in supported versions of affected applications.
HP Storage Management Appliance is affected by the issue; please see the referenced HP advisory.
Microsoft Content Management Server 2001 SP1
-
Microsoft Security Update for Microsoft Content Management Server 2001 (KB924430)
http://www.microsoft.com/downloads/details.aspx?familyid=0AAC923D-A6B8 -4023-9977-AEA6782DC1C7&displaylang=en
Microsoft Content Management Server 2002 SP2
-
Microsoft Security Update for Microsoft Content Management Server 2002 (KB924429)
http://www.microsoft.com/downloads/details.aspx?familyid=41D53931-BCF8 -43D9-9D16-592EBFB0AC04&displaylang=en
References
Microsoft Content Management Server Cross-Site Scripting Vulnerability
References:
References:
- Microsoft Content Management Server Homepage (Microsoft)
- Microsoft Security Bulletin MS07-018 (Microsoft)