DCP-Portal User Details Cross-Agent Scripting Vulnerability
BID:4112
Info
DCP-Portal User Details Cross-Agent Scripting Vulnerability
| Bugtraq ID: | 4112 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0281 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2002 12:00AM |
| Updated: | Jul 09 2007 03:47PM |
| Credit: | Discovered by Ahmet Sabri ALPER <[email protected]>. |
| Vulnerable: |
DCP-Portal DCP-Portal 4.5.1 DCP-Portal DCP-Portal 4.2 DCP-Portal DCP-Portal 4.1 DCP-Portal DCP-Portal 4.0 DCP-Portal DCP-Portal 3.7 |
| Not Vulnerable: |
DCP-Portal DCP-Portal 5.3.2 DCP-Portal DCP-Portal 5.3.1 DCP-Portal DCP-Portal 5.3 DCP-Portal DCP-Portal 5.2 DCP-Portal DCP-Portal 5.1 DCP-Portal DCP-Portal 5.0.2 |
Discussion
DCP-Portal User Details Cross-Agent Scripting Vulnerability
DCP-Portal is a content manager enables various web-based updates. An admin can remotely manage the entire site, members can submit news/content and reviews, etc.
A user of the DCP-Portal system can opt to publish some profile information. A malicious user could include JavaScript commands in some of this information. When the attacker's profile is viewed by a third party, these script commands will execute within the context of the DCP-Portal page, leading to a cross-agent scripting attack. The job information field suffers from this vulnerability.
DCP-Portal is a content manager enables various web-based updates. An admin can remotely manage the entire site, members can submit news/content and reviews, etc.
A user of the DCP-Portal system can opt to publish some profile information. A malicious user could include JavaScript commands in some of this information. When the attacker's profile is viewed by a third party, these script commands will execute within the context of the DCP-Portal page, leading to a cross-agent scripting attack. The job information field suffers from this vulnerability.
Solution / Fix
DCP-Portal User Details Cross-Agent Scripting Vulnerability
Solution:
This issue was addressed in DCP-Portal 5.0.2.
DCP-Portal DCP-Portal 3.7
DCP-Portal DCP-Portal 4.0
DCP-Portal DCP-Portal 4.1
DCP-Portal DCP-Portal 4.2
DCP-Portal DCP-Portal 4.5.1
Solution:
This issue was addressed in DCP-Portal 5.0.2.
DCP-Portal DCP-Portal 3.7
-
DCP-Portal DCP-Portal 5.3.2
http://www.dcp-portal.org/index.php?page=documents&doc=75&dlcat=1
DCP-Portal DCP-Portal 4.0
-
DCP-Portal DCP-Portal 5.3.2
http://www.dcp-portal.org/index.php?page=documents&doc=75&dlcat=1
DCP-Portal DCP-Portal 4.1
-
DCP-Portal DCP-Portal 5.3.2
http://www.dcp-portal.org/index.php?page=documents&doc=75&dlcat=1
DCP-Portal DCP-Portal 4.2
-
DCP-Portal DCP-Portal 5.3.2
http://www.dcp-portal.org/index.php?page=documents&doc=75&dlcat=1
DCP-Portal DCP-Portal 4.5.1
-
DCP-Portal DCP-Portal 5.3.2
http://www.dcp-portal.org/index.php?page=documents&doc=75&dlcat=1