[NEWS] Multiple Cross-Site Vulnerabilities Found in Leading Web Sites (IMDB, PlanetQuake, Merriam-Webster)
From: support@securiteam.comDate: 01/15/02
- Previous message: support@securiteam.com: "[EXPL] Cross-Site Scripting Vulnerability Found in PostNuke"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Tue, 15 Jan 2002 12:24:11 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Multiple Cross-Site Vulnerabilities Found in Leading Web Sites (IMDB,
PlanetQuake, Merriam-Webster)
------------------------------------------------------------------------
SUMMARY
The web sites IMDB, PlanetQuake, and Merriam-Webster suffer from
Cross-Site Scripting vulnerabilities (CSS). The vulnerability enables
attackers to enter arbitrary JavaScript commands into the output of the
web server; this would allow an attacker to send a specially crafted URL
to victims containing active script, where the URL will look as though it
is coming from the trusted web sites, when in fact they it will be the
attacker's.
DETAILS
Examples:
http://us.imdb.com/ImageView?u=http%3A//images.amazon.com/images/P/"%20%
3eonmouseover=alert(document.domain);>
http://www.planetquake3.net/download.php?op=viewdownloaddetails&lid=469&ttitle=""><script%
20language=javascript>alert (document.domain;</script>
http://www.m-w.com/cgi-bin/audio.pl?jackas01.wav=