Perception LiteServe Directory Query String Cross Site Scripting Vulnerability
BID:6143
Info
Perception LiteServe Directory Query String Cross Site Scripting Vulnerability
| Bugtraq ID: | 6143 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2002 12:00AM |
| Updated: | Nov 08 2002 12:00AM |
| Credit: | Vulnerability was discovered by Matthew Murphy. |
| Vulnerable: |
Perception LiteServe 2.0.1 |
| Not Vulnerable: |
Perception LiteServe 2.0 2 |
Discussion
Perception LiteServe Directory Query String Cross Site Scripting Vulnerability
A cross site scripting vulnerability has been discovered in Perception LiteServe.
It has been reported that LiteServe fails to sanitize query strings from indexed folders. It is possible for an attacker to exploit this issue by constructing a malicious link, containing encoded HTML and script code.
When the malicious link is clicked by an unsuspecting user, the attacker-supplied HTML and script code will be executed by their web client.
Attacks of this nature may make it possible for attackers to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
A cross site scripting vulnerability has been discovered in Perception LiteServe.
It has been reported that LiteServe fails to sanitize query strings from indexed folders. It is possible for an attacker to exploit this issue by constructing a malicious link, containing encoded HTML and script code.
When the malicious link is clicked by an unsuspecting user, the attacker-supplied HTML and script code will be executed by their web client.
Attacks of this nature may make it possible for attackers to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Exploit / POC
Perception LiteServe Directory Query String Cross Site Scripting Vulnerability
The following proof of concepts have been made available by "Matthew Murphy" <[email protected]>:
http://liteserve.net/dir?%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28location%2Ehref%29%22%3E
http://liteserve.net/dir?%3C%2FTITLE%3E%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28location%2Ehref%29%22%3E
The following proof of concepts have been made available by "Matthew Murphy" <[email protected]>:
http://liteserve.net/dir?%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28location%2Ehref%29%22%3E
http://liteserve.net/dir?%3C%2FTITLE%3E%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28location%2Ehref%29%22%3E
Solution / Fix
Perception LiteServe Directory Query String Cross Site Scripting Vulnerability
Solution:
Perception has released a new version of the software addressing this issue. Users are advised to upgrade as soon as possible.
Perception LiteServe 2.0.1
Solution:
Perception has released a new version of the software addressing this issue. Users are advised to upgrade as soon as possible.
Perception LiteServe 2.0.1
-
Perception LiteServe v2.02
http://www.liteserve.net
References
Perception LiteServe Directory Query String Cross Site Scripting Vulnerability
References:
References:
- LiteServe Directory Index Cross-Site Scripting ("Matthew Murphy"
)