Tmax Soft JEUS URL.JSP Cross-Site Scripting Vulnerability
BID:7969
Info
Tmax Soft JEUS URL.JSP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7969 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2003 12:00AM |
| Updated: | Jun 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Jeremy Bae at STG Security SSR Team. |
| Vulnerable: |
Tmax Soft JEUS 3.1.4 p1 |
| Not Vulnerable: |
Tmax Soft JEUS 3.2.2 |
Discussion
Tmax Soft JEUS URL.JSP Cross-Site Scripting Vulnerability
Reportedly, Tmax Soft JEUS is vulnerable to a cross site-scripting attack. The vulnerability is present in the url.jsp script of the Tmax Soft JEUS server.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link.
It should be noted that although this vulnerability has been reported to affect Tmax Soft JEUS version 3.1.4p1, all version prior to release 3.2.2 are also reported vulnerable.
Reportedly, Tmax Soft JEUS is vulnerable to a cross site-scripting attack. The vulnerability is present in the url.jsp script of the Tmax Soft JEUS server.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link.
It should be noted that although this vulnerability has been reported to affect Tmax Soft JEUS version 3.1.4p1, all version prior to release 3.2.2 are also reported vulnerable.
Exploit / POC
Tmax Soft JEUS URL.JSP Cross-Site Scripting Vulnerability
The following proof of concept has been supplied:
http://www.example.com/url.jsp?foo=<script>alert('XSS vulnerability
exists!')</script>
The following proof of concept has been supplied:
http://www.example.com/url.jsp?foo=<script>alert('XSS vulnerability
exists!')</script>
References
Tmax Soft JEUS URL.JSP Cross-Site Scripting Vulnerability
References:
References:
- Tmax Soft JEUS Homepage (Tmax Soft)