by r0t,der4444,cembo,VietMafia

Tuesday, December 06, 2005

IISWorks ASP KnowledgeBase 2.x XSS vuln.

IISWorks ASP KnowledgeBase 2.x XSS vuln.
Vuln. dicovered by : r0t
Date: 6 dec. 2005
vendor:http://www.iisworks.com/aspkb/
affected version:2.x and prior

Product Description:
100% ASP based Knowledge base application that uses a simple MS Access or robust MS SQL database to store articles, FAQ's, etc. in an organized way. Features: Powerful search engine, Clean and intuitive interface, Highly configurable display, Web admin to add, edit and archive articles and categories, Add related downloads to articles, Refer to related articles, User poll, Email feedback, and Article hit counter. Language module support, Logging, NT Authentication.

Vuln. Description:
ASP based Knowledge contains a flaw that allows a remote cross site scripting attack. This flaw exists because input passed to the "a" paremter in "kb.asp" isn't properly sanitised before being returned to the user.
This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

example:

/kb.asp?a=%22%3E%3Cscript%3E
alert('r0t')%3C/script%3E

/kb.asp?ID=210&a=%22%3E%3Cscript
%3Ealert('r0t')%3C/script%3E

Solution:
Edit the source code to ensure that input is properly sanitised.

0 Comments:

Post a Comment

<< Home

 
Copyright (c) 2006 Pridels Sec Crew