Macromedia JRun Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
BID:9112
Info
Macromedia JRun Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 9112 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2003 12:00AM |
| Updated: | Nov 26 2003 12:00AM |
| Credit: | This vulnerability was reported by [email protected]. |
| Vulnerable: |
Macromedia JRun 4.0 build 61650 |
| Not Vulnerable: | |
Discussion
Macromedia JRun Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
A number of cross-site scripting vulnerabilities have been reported for Macromedia Jrun, specifically in the administrative interface. The problem is said to occur due to insufficient sanitization of URI parameters that may be passed to the page by an unauthenticated user.
Successful exploitation of this issue could potentially allow an attacker to steal an administrators authentication credentials, likely leading to further malicious actions taking places.
A number of cross-site scripting vulnerabilities have been reported for Macromedia Jrun, specifically in the administrative interface. The problem is said to occur due to insufficient sanitization of URI parameters that may be passed to the page by an unauthenticated user.
Successful exploitation of this issue could potentially allow an attacker to steal an administrators authentication credentials, likely leading to further malicious actions taking places.
Exploit / POC
Macromedia JRun Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
The following proof of concept requests have been provided:
http://www.example.com:8000/server/<your server>/webserver/webserverlist.jsp?action=start&externalWebServer=DefaultDomain%3aservice%3d<script code>
http://www.example.com:8000/clusterframe.jsp?cluster=<script code>
The following proof of concept requests have been provided:
http://www.example.com:8000/server/<your server>/webserver/webserverlist.jsp?action=start&externalWebServer=DefaultDomain%3aservice%3d<script code>
http://www.example.com:8000/clusterframe.jsp?cluster=<script code>
Solution / Fix
Macromedia JRun Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Macromedia JRun Administrative Interface Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- JRun Homepage (Adobe)
- Macromedia Homepage (Macromedia)