Macromedia Allaire Forums and Spectra Cross Site Scripting Vulnerability
BID:4446
Info
Macromedia Allaire Forums and Spectra Cross Site Scripting Vulnerability
| Bugtraq ID: | 4446 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2000 12:00AM |
| Updated: | Feb 17 2000 12:00AM |
| Credit: | Published in a Macromedia Allaire Security Bulletin (ASB00-05). |
| Vulnerable: |
Allaire Spectra 1.5.1 Allaire Spectra 1.5 Allaire Forums 2.0.5 Allaire Forums 2.0.4 Allaire Forums 2.0.3 Allaire Forums 2.0.2 Allaire Forums 2.0.1 Allaire Forums 2.0 |
| Not Vulnerable: | |
Discussion
Macromedia Allaire Forums and Spectra Cross Site Scripting Vulnerability
Macromedia Allaire Forums is a web-based threaded discussion application used to host conferences. Forums is maintained jointly by Macromedia and Allaire.
Macromedia Allaire Spectra provides online business sites the ability to incorporate content management, e-commerce, and personalization within one application.
It is possible to insert user supplied HTML code, including script commands, into a Forums or Spectra generated page. This can be done through the use of a maliciously constructed URL to the vulnerable Forums system.
If a legitimate user of the service is enticed into following such a link, the malicious script code will execute within the context of that page.
Macromedia Allaire Forums is a web-based threaded discussion application used to host conferences. Forums is maintained jointly by Macromedia and Allaire.
Macromedia Allaire Spectra provides online business sites the ability to incorporate content management, e-commerce, and personalization within one application.
It is possible to insert user supplied HTML code, including script commands, into a Forums or Spectra generated page. This can be done through the use of a maliciously constructed URL to the vulnerable Forums system.
If a legitimate user of the service is enticed into following such a link, the malicious script code will execute within the context of that page.
Exploit / POC
Macromedia Allaire Forums and Spectra Cross Site Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Macromedia Allaire Forums and Spectra Cross Site Scripting Vulnerability
Solution:
JRun and ColdFusion administrators are recommended to read the following Security Best Practice:
http://www.macromedia.com/v1/handlers/index.cfm?ID=14558&Method=Full
Solution:
JRun and ColdFusion administrators are recommended to read the following Security Best Practice:
http://www.macromedia.com/v1/handlers/index.cfm?ID=14558&Method=Full