SAP Internet Transaction Server Cross Site Scripting Vulnerability
BID:8517
Info
SAP Internet Transaction Server Cross Site Scripting Vulnerability
| Bugtraq ID: | 8517 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0749 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | This vulnerability was reported by Martin Eiszner <[email protected]>. |
| Vulnerable: |
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 |
| Not Vulnerable: | |
Discussion
SAP Internet Transaction Server Cross Site Scripting Vulnerability
The 'wgate.dll' componenet of SAP Internet Transaction Server has been reported prone to cross-site scripting attacks. The issue occurs due to a lack of sufficient sanitization performed on data supplied to the 'wgate.dll' library. Exploitation could allow theft of cookie-based authentication credentials or other attacks
The 'wgate.dll' componenet of SAP Internet Transaction Server has been reported prone to cross-site scripting attacks. The issue occurs due to a lack of sufficient sanitization performed on data supplied to the 'wgate.dll' library. Exploitation could allow theft of cookie-based authentication credentials or other attacks
Exploit / POC
SAP Internet Transaction Server Cross Site Scripting Vulnerability
The following proof of concept example has been supplied:
http://www.server.name/scripts/wgate.dll?
with params:
~service=--><img%09src=javascript:alert(1)%3bcrap
The following proof of concept example has been supplied:
http://www.server.name/scripts/wgate.dll?
with params:
~service=--><img%09src=javascript:alert(1)%3bcrap
Solution / Fix
SAP Internet Transaction Server Cross Site Scripting Vulnerability
Solution:
It has been reported that this issue has been addressed by SAP, however this information has not been confirmed by Symantec. Users are advised to contact SAP for any further details regarding available fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that this issue has been addressed by SAP, however this information has not been confirmed by Symantec. Users are advised to contact SAP for any further details regarding available fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SAP Internet Transaction Server Cross Site Scripting Vulnerability
References:
References:
- SAP Internet Transaction Server (Martin Eiszner
)