Cross-Site Scripting Vulnerability in Macromedia Sitespring

cross-site scripting vulnerability exists in the default error page of Macromedia’s Sitespring.

Ken Pfeil

July 18, 2002

1 Min Read
ITPro Today logo

Reported July 17, 2002, by PeterGründl.

VERSION AFFECTED

 

  • Macromedia Sitespring 2.0 for Windows 2000 Server

 

DESCRIPTION

A cross-site scripting vulnerability exists in the default error pageof Macromedia’s Sitespring. Because the defaultHTTP 500 error script doesn't check the contents of the error ticket parameterbefore outputting it, an attacker can inject JavaScript into the URL.

 


VENDOR RESPONSE

 

Thevendor, Macromedia, hasn't released afix for this vulnerability, but affected users can work around the problem byreplacing the default HTTP 500 error page with a custom page.

 

CREDIT
Discovered by PeterGründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like