Multiple Vignette Cross-Site Scripting Vulnerabilities
BID:7687
Info
Multiple Vignette Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 7687 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0404 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to Ramon Pinuaga Cascales <[email protected]>. |
| Vulnerable: |
Vignette Vignette V/5 Vignette V6 Content Suite Vignette StoryServer 5.0 Vignette StoryServer 4.1 Vignette StoryServer 4.0 Vignette Content Suite V7 Vignette Content Suite V5 |
| Not Vulnerable: | |
Discussion
Multiple Vignette Cross-Site Scripting Vulnerabilities
Vignette software has been reported prone to multiple cross-site scripting vulnerabilities.
Reportedly the issue presents itself, because the Vignette software does not sufficiently sanitize HTML characters from user-supplied data.
It may be possible for an attacker to supply and execute HTML and script code on a web client in the context of the site hosting the Vignette software. This may allow for theft of cookie-based authentication credentials and other attacks.
This issue was reported for Vignette StoryServer version 4 to version 6; it has been speculated that all current versions are vulnerable.
Vignette software has been reported prone to multiple cross-site scripting vulnerabilities.
Reportedly the issue presents itself, because the Vignette software does not sufficiently sanitize HTML characters from user-supplied data.
It may be possible for an attacker to supply and execute HTML and script code on a web client in the context of the site hosting the Vignette software. This may allow for theft of cookie-based authentication credentials and other attacks.
This issue was reported for Vignette StoryServer version 4 to version 6; it has been speculated that all current versions are vulnerable.
Exploit / POC
Multiple Vignette Cross-Site Scripting Vulnerabilities
The following proof of concepts have been supplied:
https://www.example.com/Page/1,10966,,00.html?var=<script>alert('s21sec')</script>
http://www.example.com/vgn/login?errInfo="%2b%20document.cookie%20%2b"
The following proof of concepts have been supplied:
https://www.example.com/Page/1,10966,,00.html?var=<script>alert('s21sec')</script>
http://www.example.com/vgn/login?errInfo="%2b%20document.cookie%20%2b"
Solution / Fix
Multiple Vignette Cross-Site Scripting Vulnerabilities
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
The vendor has released a fix to address this issue. Vignette customers who are affected by this vulnerability have been advised to contact Vignette, using standard methods, as soon as possible to attain the required fixes.
Solution:
The vendor has posted a response to this issue at the following location:
http://support.vignette.com/VOLSS/KB/View/1,,5557,00.html
It should be noted that only existing Vignette customers and partners are able to access the above link.
The vendor has released a fix to address this issue. Vignette customers who are affected by this vulnerability have been advised to contact Vignette, using standard methods, as soon as possible to attain the required fixes.
References
Multiple Vignette Cross-Site Scripting Vulnerabilities
References:
References:
- Multiple Cross Site Scripting vulnerabilities in Vignette (Ramon Pinuaga Cascales)
- Vignette Homepage (VIGNETTE)
- S21SEC-023 - Vignette multiple Cross Site Scripting vulnerabilities (S21SEC
)