ASP-Nuke Cross-Agent Scripting Vulnerability
BID:4481
Info
ASP-Nuke Cross-Agent Scripting Vulnerability
| Bugtraq ID: | 4481 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0521 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
ASP-Nuke ASP-Nuke RC2 ASP-Nuke ASP-Nuke RC1 |
| Not Vulnerable: |
ASP-Nuke ASP-Nuke RC3 |
Discussion
ASP-Nuke Cross-Agent Scripting Vulnerability
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
ASP-Nuke does not sufficiently sanitize potentially malicious characters, such as HTML tags, from user profile pages. As a result, it may be possible to inject arbitrary script code into pages that are generated by profiles.asp. The script will execute when the malicious profiles are viewed.
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
ASP-Nuke does not sufficiently sanitize potentially malicious characters, such as HTML tags, from user profile pages. As a result, it may be possible to inject arbitrary script code into pages that are generated by profiles.asp. The script will execute when the malicious profiles are viewed.
Exploit / POC
ASP-Nuke Cross-Agent Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ASP-Nuke Cross-Agent Scripting Vulnerability
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
References
ASP-Nuke Cross-Agent Scripting Vulnerability
References:
References:
- ASP-Nuke : RC1, RC2 (frog frog )
- ASP-Nuke Homepage (ASP-Nuke)