what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Exploit Labs Security Advisory 2005.8

Exploit Labs Security Advisory 2005.8
Posted Aug 7, 2005
Authored by Donnie Werner, Exploit Labs | Site exploitlabs.com

Site Studio guestbook does not filter HTML code from user-supplied input. A remote user can create a specially crafted entry that, when the page rendered, will cause arbitrary scripting to be executed by the user's browser.

tags | advisory, remote, arbitrary
SHA-256 | d1ecee131bdc6efb5f7fa557e952149ebfb57fd6db7044011a2e7d9c08c7f7ee

Exploit Labs Security Advisory 2005.8

Change Mirror Download
------------------------------------------------------------
- EXPL-A-2005-008 exploitlabs.com Advisory 037 -
------------------------------------------------------------
- Site Studio -






AFFECTED PRODUCTS
=================
Site Studio

Positive Software Corporation
https://www.psoft.net




OVERVIEW
========
SiteStudio is industry leading browser-based web site design
and construction tool. It may also be fully and seamlessly integrated
with H-Sphere. By using SiteStudio you add value to your Internet
service by providing your customers with the easiest way to build
a website. With SiteStudio, your users need not know anything
about FTP, HTML, Telnet, HTTP, or imaging software. If they can
surf the Internet, they can build their own professionally looking
website.

note: Site Studio runs via Coyote/Jakarta on port 8080 by default



DETAILS
=======
1. persistant XSS in the guestbook

Site Studio guestbook does not filter HTML code from user-supplied
input. A remote user can create a specially crafted entry that,
when the page rendered, will cause arbitrary scripting to be
executed by the user's browser. The code will originate from
the site running the Site Studio software and will run in the
security context of that site.



Item 1
---------

entering XSS type scripting in the name input field causes the
script to be rendered upon visitation to the affected the page.

a.
Standalone Site Studio installations may be accessable on the target site
via:

psoft.guestbook.GuestBookServ

https://[HOST]:8080/studio/servlet/psoft.guestbook.GuestBookServ



b.
Integrated Site Studio with H-Sphere may be accessable on the target site
via:

E-Guest_sign.pl

https://[host]/cp/Scripts/perl/guestbook/E-Guest_sign.pl





SOLUTION:
=========
Psoft has been contacted and patches released:

item a:
https://www.psoft.net/SS/ss_16_security_update_guestbook.html

item b:
https://www.psoft.net/misc/hsphere_winbox_security_update_guestbook.html




Credits
=======
This vulnerability was discovered and researched by
Donnie Werner of exploitlabs

Donnie Werner

mail: wood at exploitlabs.com
mail: morning_wood at zone-h.org
--
web: https://exploitlabs.com
web: https://zone-h.org

https://exploitlabs.com/files/advisories/EXPL-A-2005-008-sitestudio.txt
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close