Verity Information Server Cross Site Scripting Vulnerability
BID:7205
Info
Verity Information Server Cross Site Scripting Vulnerability
| Bugtraq ID: | 7205 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2003 12:00AM |
| Updated: | Mar 26 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "decka trash" <[email protected]>. |
| Vulnerable: |
Verity Inc. Verity Information Server |
| Not Vulnerable: | |
Discussion
Verity Information Server Cross Site Scripting Vulnerability
It has been reported that Verity Information Server does not sufficiently filter user-supplied search parameters on the Verity Information Server 'Search' page.
It may be possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user. All code will be executed within the context of the website running Verity Information Server.
It has been reported that Verity Information Server does not sufficiently filter user-supplied search parameters on the Verity Information Server 'Search' page.
It may be possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user. All code will be executed within the context of the website running Verity Information Server.
Exploit / POC
Verity Information Server Cross Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Verity Information Server Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Verity Information Server Cross Site Scripting Vulnerability
References:
References:
- Company Homepage (Verity)
- Verity Information Server XSS (www.securitybugware.org)