Macromedia Sitespring Default Error Page Cross Site Scripting Vulnerability
BID:5249
Info
Macromedia Sitespring Default Error Page Cross Site Scripting Vulnerability
| Bugtraq ID: | 5249 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1027 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2002 12:00AM |
| Updated: | Nov 06 2006 08:42PM |
| Credit: | Discovered by Peter Gründl <[email protected]>. |
| Vulnerable: |
Macromedia Sitespring 1.2 .0 |
| Not Vulnerable: | |
Discussion
Macromedia Sitespring Default Error Page Cross Site Scripting Vulnerability
Macromedia Sitespring is a J2EE-compliant product for managing website production. The Macromedia Sitespring server runs on Microsoft Windows operating systems.
A cross-site scripting issue has been reported in the default error page used by Sitespring. When an HTTP 500 error is returned, some user-supplied data is included in the generated HTML. Since this data isn't properly sanitized, an attacker may be able to include arbitrary HTML, including JavaScript.
Macromedia Sitespring is a J2EE-compliant product for managing website production. The Macromedia Sitespring server runs on Microsoft Windows operating systems.
A cross-site scripting issue has been reported in the default error page used by Sitespring. When an HTTP 500 error is returned, some user-supplied data is included in the generated HTML. Since this data isn't properly sanitized, an attacker may be able to include arbitrary HTML, including JavaScript.
Exploit / POC
Macromedia Sitespring Default Error Page Cross Site Scripting Vulnerability
No exploit is required. The following example has been provided by Peter Gründl <[email protected]>:
http://server/error/500error.jsp?et=1<script>alert('KPMG')</script>
No exploit is required. The following example has been provided by Peter Gründl <[email protected]>:
http://server/error/500error.jsp?et=1<script>alert('KPMG')</script>