Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  [SA18136] ShopEngine "EXPS" Cross-Site Scripting Vulnerability

  [ GLSA 200512-12 ] Mantis: Multiple vulnerabilities

  XSS&Sql injection attack in PHP-Fusion 6.00.3 Released

  [Full-disclosure] SEC Consult SA-20051223-1 :: File Disclosure using df_next_page parameter in OracleAS Discussion Forum Portlet

From:r0t <krustevs_(at)_googlemail.com>
Date:23.12.2005
Subject:CommonSpot Content Server vuln.

CommonSpot Content Server vuln.

Vuln. discovered by : r0t
Date: 23 dec. 2005
orginal advisory:http://pridels.blogspot.com/2005/12/commonspot-content-server-vuln.html
vendor:http://www.paperthin.com/
affected version:4.5 and prior


Product Description:

PaperThin's award-winning technology enables our customers to meet their business objectives. With CommonSpot Content Server, organizations can quickly build and easily maintain dynamic, personalized and sophisticated sites.
CommonSpot scales to meet the Web publishing and content management needs of the most demanding sites, and is used by more than 200 organizations of all sizes worldwide.


Vuln. Description:

CommonSpot Content Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because input passed to "NewWindow" paremter isn't properly sanitised before being returned to the user.
This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

poc:

XSS:
/loader.cfm?url=/[DIRPATH]/[DIRPATH]/email
-login-info.cfm&errmsg=No%20user%20account
%20was%20found%20for%20that%20email%20addr
ess.%20%20Please%20try%20again.&bNewWindo
w=[XSS]

full path:
/loader.cfm?url=/[DIRPATH]/[DIRPATH]/email
-login-info.cfm&errmsg=[CODE]


Solution:
Edit the source code to ensure that input is properly sanitised.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru