[Full-Disclosure] STG Security Advisory: JEUS Web Application Server Cross Site Scripting Vulnerability
From: SSR Team (advisory_at_stgsecurity.com)
Date: 06/17/03
- Previous message: Justin Shin: "[Full-Disclosure] weasel32"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: "Full Disclosure" <full-disclosure@lists.netsys.com> Date: Tue, 17 Jun 2003 10:19:55 +0900
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
STG Security Advisory: JEUS Web Application Server Cross Site Scripting
Vulnerability
Revision: 1.0
Date Published: 2003-06-17 (KST)
Last Update: 2003-06-17
Product Description
=========
JEUS (Java Enterprise User Solution) is a J2EE compatible web application
server, developed by Tmax Soft, providing a clustering system especially
designed for large enterprise business applications.
Vulnerability Class
================
Implementation Error: Inappropriate Input Validation
Affected Products
================
This vulnerability was found at JEUS 3.1.4p1. The vendor confirmed all
versions below 3.2.2 have this vulnerability.
Details
======
JEUS Web Application Server has a cross site scripting vulnerability
invoking a JavaScript as following:
Proof of Concept
http://vulnerable.com/url.jsp?foo=