Sun ONE Application Server Error Message Cross-Site Scripting Vulnerability
BID:7710
Info
Sun ONE Application Server Error Message Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7710 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0413 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to "SPI Labs" <[email protected]>. |
| Vulnerable: |
Sun ONE Application Server 7.0 Standard Edition Sun ONE Application Server 7.0 Platform Edition Sun Java System Web Server 6.1 SP1 Sun Java System Web Server 6.1 |
| Not Vulnerable: |
Sun ONE Application Server 7.0 UR1 Standard Edition Sun ONE Application Server 7.0 UR1 Platform Edition Sun Java System Web Server 6.1 SP2 |
Discussion
Sun ONE Application Server Error Message Cross-Site Scripting Vulnerability
Sun ONE Application Server has been reported prone to a cross-site scripting vulnerability.
Sun ONE Application Server does not adequately filter script code from URL parameters, making it prone to cross-site scripting attacks. Attacker-supplied script code may be included in a malicious link to a JSP application hosted on the vulnerable server. Under some circumstances if this link is followed the code will be executed in the browser of the web user who visits the link.
This issue affects a sample script supplied with the server. The vendor has reported that the sample application 'webapps-simple' affected by this issue is not enabled by default.
This vulnerability has been reported to affect Sun ONE Application Server 6.1, 6.1 Service Pack 1, and 7.0 on Windows platforms.
Sun ONE Application Server has been reported prone to a cross-site scripting vulnerability.
Sun ONE Application Server does not adequately filter script code from URL parameters, making it prone to cross-site scripting attacks. Attacker-supplied script code may be included in a malicious link to a JSP application hosted on the vulnerable server. Under some circumstances if this link is followed the code will be executed in the browser of the web user who visits the link.
This issue affects a sample script supplied with the server. The vendor has reported that the sample application 'webapps-simple' affected by this issue is not enabled by default.
This vulnerability has been reported to affect Sun ONE Application Server 6.1, 6.1 Service Pack 1, and 7.0 on Windows platforms.
Exploit / POC
Sun ONE Application Server Error Message Cross-Site Scripting Vulnerability
The following proof of concept has been supplied:
GET /webapps-simple/jsp/source.jsp?<script>alert(document.cookie)</script>
HTTP/1.0
The following proof of concept has been supplied:
GET /webapps-simple/jsp/source.jsp?<script>alert(document.cookie)</script>
HTTP/1.0
Solution / Fix
Sun ONE Application Server Error Message Cross-Site Scripting Vulnerability
Solution:
Sun has released alert 57605 addressing this issue. Please see the referenced alert for further information.
The following fixes are available:
Sun Java System Web Server 6.1 SP1
Sun Java System Web Server 6.1
Sun ONE Application Server 7.0 Platform Edition
Sun ONE Application Server 7.0 Standard Edition
Solution:
Sun has released alert 57605 addressing this issue. Please see the referenced alert for further information.
The following fixes are available:
Sun Java System Web Server 6.1 SP1
-
Sun Sun Java System Web Server 6.1 Service Pack 2
http://wwws.sun.com/software/download/products/40883612.html
Sun Java System Web Server 6.1
-
Sun Sun Java System Web Server 6.1 Service Pack 2
http://wwws.sun.com/software/download/products/40883612.html
Sun ONE Application Server 7.0 Platform Edition
-
Sun Sun ONE Application Server 7.0 Update Release 1
http://wwws.sun.com/software/download/products/3ec1008e.html
Sun ONE Application Server 7.0 Standard Edition
-
Sun Sun ONE Application Server 7.0 Update Release 1
http://wwws.sun.com/software/download/products/3ec1008e.html -
Sun Sun ONE Application Server 7.0 Update Release 1
http://wwws.sun.com/software/download/products/3ec3e772.html
References
Sun ONE Application Server Error Message Cross-Site Scripting Vulnerability
References:
References:
- Multiple Vulnerabilities in Sun-One Application Server (SPI Dynamics)
- Sun Alert ID: 55221 (Sun)
- Sun Alert ID: 57605 (Sun)
- Sun ONE Application Server Homepage (Sun)
- Sun[tm] ONE Web Server (Sun)
- Multiple Vulnerabilities in Sun-One Application Server ("SPI Labs"
)