[NEWS] JEUS Web Application Server Cross Site Scripting Vulnerability
From: SecuriTeam (support_at_securiteam.com)
Date: 06/18/03
- Previous message: SecuriTeam: "[REVS] Exploitation of Data Streams Authorized by a Network Access Control System for Arbitrary Data Transfers: Tunneling and Covert Channels over the HTTP Protocol"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 18 Jun 2003 15:48:56 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
Latest attack techniques.
You're a pen tester, but is google.com still your R&D team?
Now you can get trustworthy commercial-grade exploits and the latest
techniques from a world-class research group.
Learn more at http://www.coresecurity.com/promos/sit_e1,
or call 617-399-6980
- - - - - - - - -
JEUS Web Application Server Cross Site Scripting Vulnerability
------------------------------------------------------------------------
SUMMARY
<http://www.tmaxsoft.com/products/jeus/jeus_overview.html> JEUS (Java
Enterprise User Solution) is a J2EE compatible web application server,
developed by Tmax Soft, providing a clustering system especially designed
for large enterprise business applications. A cross site scripting
vulnerability has been discovered in the product allowing remote attackers
to cause the product to incoporate malicious HTML and JavaScript into
existing web pages.
DETAILS
Vulnerable systems:
* JEUS version 3.1.4p1
* JEUS versions below 3.2.2
JEUS Web Application Server Error Page has a cross site scripting
vulnerability issue when invoking a non-exists URL like below.
Example:
http://vulnerable.com/url.jsp?foo=< script>alert('XSS vulerability
exists!')</script>
Solutions:
STG Security has notified this vulnerability to the vendor, which fixed
this problem and released JEUS 3.2.2 on October 2002.
More detail information is found at <http://www.tmax.co.kr>
http://www.tmax.co.kr.
Vendor status:
2002-10-12 Tmax Soft notified.
2002-10-17 Second attempt at vendor contact.
2002-10-17 Fixed version released.
2003-05-21 Last attempt at vendor contact.
2003-05-23 Public disclosure.
ADDITIONAL INFORMATION
The information has been provided by <mailto:swbae@stgsecurity.com>
Jeremy Bae at STG Security SSR Team.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[REVS] Exploitation of Data Streams Authorized by a Network Access Control System for Arbitrary Data Transfers: Tunneling and Covert Channels over the HTTP Protocol"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [DRUPAL-SA-2007-018] Drupal 4.7.7 and 5.2 fix multiple cross site scripting vulnerabilit
... Both vulnerabilities are know as cross site scripting. ... The server
variables issue was reported by David Caylor. ... The security team whishes to thank
Dave, Morten Wulff, Brenda Wallace, ... (Bugtraq) - Re: [Full-disclosure] WebScarab <= 20060621-0003 cross site scripting
... SECURITY at MORITZ hyphon NAUMANN d0t COM ... WebScarab is subject to
a client side script code injection ... Cross Site Scripting, also known as XSS
or CSS, describes ... (Full-Disclosure) - Re: WebScarab <= 20060621-0003 cross site scripting
... SECURITY at MORITZ hyphon NAUMANN d0t COM ... WebScarab is subject to
a client side script code injection ... Cross Site Scripting, also known as XSS
or CSS, describes ... (Bugtraq) - Re: ADP PICK database connect to SQL
... You are taking a terribly narrow view of security. ... worse) your server.
... Google around for cross site scripting exploits. ... your 'secure' web UI's
techniques and can be _very_ nasty. ... (comp.databases.pick) - [Full-disclosure] WebScarab <= 20060621-0003 cross site scripting
... SECURITY at MORITZ hyphon NAUMANN d0t COM ... WebScarab is subject to
a client side script code injection ... Cross Site Scripting, also known as XSS
or CSS, describes ... (Full-Disclosure)