ASP-Nuke Cross Site Scripting Vulnerability
BID:4477
Info
ASP-Nuke Cross Site Scripting Vulnerability
| Bugtraq ID: | 4477 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0521 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
ASP-Nuke ASP-Nuke RC2 ASP-Nuke ASP-Nuke RC1 |
| Not Vulnerable: |
ASP-Nuke ASP-Nuke RC3 |
Discussion
ASP-Nuke Cross Site Scripting Vulnerability
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
A Cross Site Scripting issue has been reported in some versions of ASP-Nuke. The pages downloads.asp and post.asp build HTML content including user supplied input which is not properly stripped of scripting commands. An attacker may construct a link to either page which includes malicious script, which will execute within the context of the ASP-Nuke site when the link is followed.
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
A Cross Site Scripting issue has been reported in some versions of ASP-Nuke. The pages downloads.asp and post.asp build HTML content including user supplied input which is not properly stripped of scripting commands. An attacker may construct a link to either page which includes malicious script, which will execute within the context of the ASP-Nuke site when the link is followed.
Solution / Fix
ASP-Nuke Cross Site Scripting Vulnerability
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
References
ASP-Nuke Cross Site Scripting Vulnerability
References:
References:
- ASP-Nuke : RC1, RC2 (frog frog )
- ASP-Nuke Homepage (ASP-Nuke)