Affected Versions:
SiteServer CMS 3.3.9
Program introduction:
SiteServer CMS website content management system is a CMS Content Management system located in the medium and high-end markets, able to build a website platform with complete functions, excellent performance, and large scale with the lowest cost and the least manpower investment in the shortest time
Vulnerability Analysis:
Cross-site Scripting vulnerability caused by lax filtering of multiple pages such as register. aspx
Vulnerability exploitation:
1. The registration page filters out cross-site errors caused by Invalid parameters submitted by users. insert a cross-site statement:
[XSS> http://demo.siteserver.cn/usercenter/register.aspx? ReturnUrl = "> [XSS]
2. After Entering the user management program, insertion of personal signatures and space descriptions into cross-site statements can cause cross-site Vulnerabilities
Post: <iframe src = http://www.target.com>
Solution:
Vendor patch:
SiteServer CMS
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.siteserver.cn/