Microsoft IIS Redirection Error Page Cross-Site Scripting Vulnerability
BID:7731
Info
Microsoft IIS Redirection Error Page Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7731 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0223 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery is credited to SPIDynamics SPI Labs. |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 |
| Not Vulnerable: |
Microsoft IIS 6.0 |
Discussion
Microsoft IIS Redirection Error Page Cross-Site Scripting Vulnerability
Microsoft IIS is prone to a cross-site scripting vulnerability in the redirection error page. An attacker could exploit this issue by enticing a web user to a malicious link which contains hostile HTML or script code. This code may be rendered in the user's browser when the redirection error page is displayed.
Microsoft IIS is prone to a cross-site scripting vulnerability in the redirection error page. An attacker could exploit this issue by enticing a web user to a malicious link which contains hostile HTML or script code. This code may be rendered in the user's browser when the redirection error page is displayed.
Solution / Fix
Microsoft IIS Redirection Error Page Cross-Site Scripting Vulnerability
Solution:
Microsoft has released updates.
There is a dependency associated with this patch. It requires the patch from Microsoft Security Bulletin MS02-050 to be installed. If this patch is installed and MS02-050 is not present, client side certificates will be rejected. This functionality can be restored by installing the MS02-050 patch.
Microsoft IIS 5.1
Microsoft IIS 4.0
Microsoft IIS 5.0
Solution:
Microsoft has released updates.
There is a dependency associated with this patch. It requires the patch from Microsoft Security Bulletin MS02-050 to be installed. If this patch is installed and MS02-050 is not present, client side certificates will be rejected. This functionality can be restored by installing the MS02-050 patch.
Microsoft IIS 5.1
-
Microsoft Q811114
For Windows XP 32-bit edition. IIS 5.1 patch to be installed on systems running Windows XP Professional Gold and Service Pack 1.
http://microsoft.com/downloads/details.aspx?FamilyId=77CFE3EF-C5C5-401 C-BC12-9F08154A5007&displaylang=en -
Microsoft Q811114
For Windows XP 64-bit edition. IIS 5.1 patch to be installed on systems running Windows XP Professional Gold and Service Pack 1.
http://microsoft.com/downloads/details.aspx?FamilyId=86F4407E-B9BF-449 0-9421-008407578D11&displaylang=en
Microsoft IIS 4.0
-
Microsoft Q811114
IIS 4.0 patch to be installed on systems running Windows NT 4.0 Service Pack 6a.
http://microsoft.com/downloads/details.aspx?FamilyId=1DBC1914-98E9-4DE D-ADBF-E9B374A1F79D&displaylang=en
Microsoft IIS 5.0
-
Microsoft Q811114
IIS 5.0 patch to be installed on systems running Windows 2000 Service Pack 2 or Service Pack 3.
http://microsoft.com/downloads/details.aspx?FamilyId=2F5D9852-4ADD-44F 8-8715-AC3D7D7D94BF&displaylang=en
References
Microsoft IIS Redirection Error Page Cross-Site Scripting Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-050 (Microsoft)
- Microsoft Security Bulletin MS03-018 (Microsoft)