DCP-Portal Search.PHP Cross-Site Scripting Vulnerability
BID:7141
Info
DCP-Portal Search.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7141 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2003 12:00AM |
| Updated: | Mar 18 2003 12:00AM |
| Credit: | Discovery is credited to Ertan Kurt <[email protected]>. |
| Vulnerable: |
DCP-Portal DCP-Portal 5.3.1 |
| Not Vulnerable: | |
Discussion
DCP-Portal Search.PHP Cross-Site Scripting Vulnerability
DCP-Portal is prone to cross-site scripting attacks. This is due to insufficient sanitization of data passed to the 'search.php' script via URI parameters. As a result, it is possible for a remote user to create a malicious link to a site hosting the vulnerable software which contains hostile HTML and script code. If the link is visited, the attacker-supplied script code and HTML may be interpreted by the user's web browser. This could allow for compromise of cookie-based credentials or other possible attacks.
DCP-Portal 5.3.1 is reported to be affected. Other versions may also be affected.
DCP-Portal is prone to cross-site scripting attacks. This is due to insufficient sanitization of data passed to the 'search.php' script via URI parameters. As a result, it is possible for a remote user to create a malicious link to a site hosting the vulnerable software which contains hostile HTML and script code. If the link is visited, the attacker-supplied script code and HTML may be interpreted by the user's web browser. This could allow for compromise of cookie-based credentials or other possible attacks.
DCP-Portal 5.3.1 is reported to be affected. Other versions may also be affected.
Exploit / POC
DCP-Portal Search.PHP Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
DCP-Portal Search.PHP Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DCP-Portal Search.PHP Cross-Site Scripting Vulnerability
References:
References:
- DCP-Portal Homepage (DCP-Portal)
- Some XSS vulns (Ertan Kurt
)