[VulnWatch] Zaep AntiSpam Cross Site Scripting

From: Aviram Jenik (aviram_at_beyondsecurity.com)
Date: 04/19/04

  • Next message: Aviram Jenik: "[VulnWatch] KPhone STUN DoS (Malformed STUN Packets)"
    To: vulnwatch@vulnwatch.org
    Date: Mon, 19 Apr 2004 15:11:21 +0300
    
    

     Zaep AntiSpam Cross Site Scripting
    ------------------------------------------------------------------------

    Article reference:
    http://www.securiteam.com/windowsntfocus/5EP0I15CKK.html

    SUMMARY

    Beyond Security has discovered a security vulnerability in
    <http://www.zaep.com/> Zaep AntiSpam 2.0, the vulnerability would allow a
    remote attacker to use the Zaep program's CGI to cause it to return third
    party content as if it were its own (A cross-site scripting vulnerability).
    This vulnerability would allow (depending on the web server's configuration
    and site sensitivity) to steal cookies, display alternative information
    (cross-site defacement), or redirect users to malicious sites.

    DETAILS

    Vulnerable Systems:
     * Zaep AntiSpam 2.0

    Immune Systems:
     * Zaep AntiSpam 2.0.0.2

    Once you send an email to an organization protected by Zaep, a URL like:
    http://vulnerable.zaep/?key=3d981f0f.4056b0a6.23285275 is issued. If you
    modify the URL to include <script>something</script>, the Zaep will convert
    the '/' sign to \, making the script clause not work properly. So far, this
    behavior will "protect" the product from a cross-site scripting
    vulnerability. However, double encoding the / sign (%252F) will bypass this
    conversion, and allow you to insert malicious content (JavaScript, HTML, etc)
    into the page.

    Exploit (for all the vulnerabilities):
    http://vulnerable.zaep/?key=>alert(document.cookie)<%252Fscript>

    Vendor response:
    The vendor has been very cooperative and has issued a patch to fix this
    problem as soon as they were notified.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:expert@securiteam.com> Noam
    Rathaus.

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any
    kind.
    In no event shall we be liable for any damages whatsoever including direct,
    indirect, incidental, consequential, loss of business profits or special
    damages.


  • Next message: Aviram Jenik: "[VulnWatch] KPhone STUN DoS (Malformed STUN Packets)"

    Relevant Pages

    • Zaep AntiSpam Cross Site Scripting
      ... Zaep AntiSpam Cross Site Scripting ... Beyond Security has discovered a security vulnerability in ...
      (NT-Bugtraq)
    • Zaep AntiSpam Cross Site Scripting
      ... Zaep AntiSpam Cross Site Scripting ... Beyond Security has discovered a security vulnerability in ...
      (Bugtraq)
    • [Full-Disclosure] Zaep AntiSpam Cross Site Scripting
      ... Zaep AntiSpam Cross Site Scripting ... Beyond Security has discovered a security vulnerability in ...
      (Full-Disclosure)
    • Roller Weblogger XSS vulnerability
      ... Remote exploitation of a Cross-Site Scripting vulnerability in the Roller allows an attacker to force to inject arbitrary script code into a users session, ...
      (Bugtraq)
    • [NT] Cookie Data in IE Can Be Exposed or Altered Through Script Injection
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Many web sites use cookies as a way to store information on a user's local ... customers can protect their systems by disabling active scripting. ... are not affected by the HTML mail exploit of this vulnerability because ...
      (Securiteam)