what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Exploit Labs Security Advisory 2005.8

Exploit Labs Security Advisory 2005.8
Posted Aug 7, 2005
Authored by Donnie Werner, Exploit Labs | Site exploitlabs.com

Site Studio guestbook does not filter HTML code from user-supplied input. A remote user can create a specially crafted entry that, when the page rendered, will cause arbitrary scripting to be executed by the user's browser.

tags | advisory, remote, arbitrary
SHA-256 | d1ecee131bdc6efb5f7fa557e952149ebfb57fd6db7044011a2e7d9c08c7f7ee

Exploit Labs Security Advisory 2005.8

Change Mirror Download
------------------------------------------------------------
- EXPL-A-2005-008 exploitlabs.com Advisory 037 -
------------------------------------------------------------
- Site Studio -






AFFECTED PRODUCTS
=================
Site Studio

Positive Software Corporation
https://www.psoft.net




OVERVIEW
========
SiteStudio is industry leading browser-based web site design
and construction tool. It may also be fully and seamlessly integrated
with H-Sphere. By using SiteStudio you add value to your Internet
service by providing your customers with the easiest way to build
a website. With SiteStudio, your users need not know anything
about FTP, HTML, Telnet, HTTP, or imaging software. If they can
surf the Internet, they can build their own professionally looking
website.

note: Site Studio runs via Coyote/Jakarta on port 8080 by default



DETAILS
=======
1. persistant XSS in the guestbook

Site Studio guestbook does not filter HTML code from user-supplied
input. A remote user can create a specially crafted entry that,
when the page rendered, will cause arbitrary scripting to be
executed by the user's browser. The code will originate from
the site running the Site Studio software and will run in the
security context of that site.



Item 1
---------

entering XSS type scripting in the name input field causes the
script to be rendered upon visitation to the affected the page.

a.
Standalone Site Studio installations may be accessable on the target site
via:

psoft.guestbook.GuestBookServ

http://[HOST]:8080/studio/servlet/psoft.guestbook.GuestBookServ



b.
Integrated Site Studio with H-Sphere may be accessable on the target site
via:

E-Guest_sign.pl

http://[host]/cp/Scripts/perl/guestbook/E-Guest_sign.pl





SOLUTION:
=========
Psoft has been contacted and patches released:

item a:
http://www.psoft.net/SS/ss_16_security_update_guestbook.html

item b:
http://www.psoft.net/misc/hsphere_winbox_security_update_guestbook.html




Credits
=======
This vulnerability was discovered and researched by
Donnie Werner of exploitlabs

Donnie Werner

mail: wood at exploitlabs.com
mail: morning_wood at zone-h.org
--
web: http://exploitlabs.com
web: http://zone-h.org

http://exploitlabs.com/files/advisories/EXPL-A-2005-008-sitestudio.txt
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close