Symantec Norton Internet Security Error Message Cross-Site Scripting Vulnerability
BID:8904
Info
Symantec Norton Internet Security Error Message Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8904 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2003 12:00AM |
| Updated: | Oct 27 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to KrazySnake <[email protected]>. |
| Vulnerable: |
Symantec Norton Internet Security 2003 6.0.4 .34 |
| Not Vulnerable: | |
Discussion
Symantec Norton Internet Security Error Message Cross-Site Scripting Vulnerability
It has been reported that Symantec Norton Internet Security is prone to a cross-site scripting vulnerability. The issue is reported to exist when the software blocks a restricted website and an error message containing the requested URL is returned to the user. This URL is not sanitized for malicious input therefore allowing a remote attacker to execute HTML or script code in the browser of a user running the vulnerable software. The script code would run in the context of the blocked site.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication information that could be used to launch further attacks.
Norton Internet Security 2003 v6.0.4.34 has been reported to be prone to this issue, however other versions may be affected as well.
It has been reported that Symantec Norton Internet Security is prone to a cross-site scripting vulnerability. The issue is reported to exist when the software blocks a restricted website and an error message containing the requested URL is returned to the user. This URL is not sanitized for malicious input therefore allowing a remote attacker to execute HTML or script code in the browser of a user running the vulnerable software. The script code would run in the context of the blocked site.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication information that could be used to launch further attacks.
Norton Internet Security 2003 v6.0.4.34 has been reported to be prone to this issue, however other versions may be affected as well.
Exploit / POC
Symantec Norton Internet Security Error Message Cross-Site Scripting Vulnerability
The following proof of concept has been provided:
http://www.example.com/page.cgi?<SCRIPT>alert(document.domain)</SCRIPT>
The following proof of concept has been provided:
http://www.example.com/page.cgi?<SCRIPT>alert(document.domain)</SCRIPT>
Solution / Fix
Symantec Norton Internet Security Error Message Cross-Site Scripting Vulnerability
Solution:
Symantec has released a fix to address this issue. Users are advised to download the patch through the LiveUpdate feature of the software.
Solution:
Symantec has released a fix to address this issue. Users are advised to download the patch through the LiveUpdate feature of the software.
References
Symantec Norton Internet Security Error Message Cross-Site Scripting Vulnerability
References:
References:
- Network Internet Security (NIS) Cross-Site Scripiting (Symantec)
- Norton Internet Security Product Page (Symantec)
- Norton Internet Security 2003 XSS (DigitalPranksters
)