[NEWS] Cross Site Scripting in the Translation and Infoplease Services of lycos.com

From: support@securiteam.com
Date: 03/15/02


From: support@securiteam.com
To: list@securiteam.com
Date: Fri, 15 Mar 2002 16:14:03 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Cross Site Scripting in the Translation and Infoplease Services of
lycos.com
------------------------------------------------------------------------

SUMMARY

It is possible to perform a cross site scripting (CSS) attack on the
translation and infoplease services of lycos.com.

DETAILS

The translation and infoplease services of lycos.com do not check for
hostile input and do not filter characters such as "<" or ">", so it is
possible to steal cookies.

Impact:
It is possible to steal cookies by providing the victim with a custom
lycos.com URL.

Exploit:

The only thing you have to do is enter some HTML code in the textbox or
just click on the following links:

translation.lycos.com:
alert(document.cookie)&lp=en_de&partner=demo-Lycos2-en">http://translation.lycos.com/?urltext=>alert(document.cookie)</script>&lp=en_de&partner=demo-Lycos2-en

infoplease.lycos.com:
alert(document.cookie)">
http://www.infoplease.lycos.com/search.php3?in=dictionary&query=><script>alert(document.cookie)</script>

Solution:
Lycos.com should implement a filter that checks for dangerous characters,
especially "<" and ">"

Vendor response:
Vendor has been contacted.

ADDITIONAL INFORMATION

The information has been provided by <mailto:tsr@it-checkpoint.net> tSR
member of <http://www.IT-Checkpoint.net> http://www.IT-Checkpoint.net.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [UNIX] Buffer Overflow in PostgreSQL (cash_words)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [TOOL] FlashFXP sites.dat Decryption
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [TOOL] LKL, Linux Key Logger
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [NT] Norton Antivirus Content Filter and Virus Protection Can By Passed
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [TOOL] WPoison SQL Injection Stress Testing
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)