SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities
BID:29103
Info
SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 29103 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2123 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Portcullis Security Testing Services |
| Vulnerable: |
SAP Internet Transaction Server 6200.1017.50954.0 Bu |
| Not Vulnerable: | |
Discussion
SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities
SAP Internet Transaction Server is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
These issues affect ITS 6200.1017.50954.0, Build 730827 (win32/IIS 5.0).
SAP Internet Transaction Server is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
These issues affect ITS 6200.1017.50954.0, Build 730827 (win32/IIS 5.0).
Exploit / POC
SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept URIs are available:
http://www.example.com/scripts/wgate.dll?~service=--><img%09src=javascript:alert(xss)
http://www.example.com/scripts/wgate/%22);alert('xss');alert(%22a/!
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept URIs are available:
http://www.example.com/scripts/wgate.dll?~service=--><img%09src=javascript:alert(xss)
http://www.example.com/scripts/wgate/%22);alert('xss');alert(%22a/!
Solution / Fix
SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities
Solution:
Reportedly, a solution and workaround are available through SAP note 1052053, but Symantec has not verified this. Please contact the vendor for more information.
Solution:
Reportedly, a solution and workaround are available through SAP note 1052053, but Symantec has not verified this. Please contact the vendor for more information.
References
SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- SAP Homepage (SAP)