evolve or die

beaXSS.txt

beaXSS.txt
Posted Aug 25, 2005
Authored by GomoR | Site GomoR.org

BEA WebLogic versions 8.1 SP4 and below suffer from a cross site scripting flaw in the Administration console.

tags | exploit, xss
MD5 | 75cb275908dde195433f902633155e90

beaXSS.txt

Change Mirror Download

I. DESCRIPTION

A cross-site scripting issue affects the display of error events in the
'View Error Log' feature of BEA WebLogic Administration console.

II. AFFECTED PRODUCTS

BEA WebLogic 8.1 SP4 and previous.

III. HOW TO VERIFY

1. Make a HTTP request containing XSS code to a target Web server

$ printf \
"GET /<script>alert(document.cookie)</script>GomoR HTTP/1.0\r\n\r\n" \
| nc www.example.com 80

2. Login into the Administration console
3. Go to the menu 'Network configurations/servers/myserser/'
4. Click on 'View server log'
5. Search for the string GomoR and click on the BEA-id event.

A JavaScript dialog box should appear.

IV. SEVERITY

I let each customer evaluate that within their own context.

V. DISCLOSURE TIMELINE

06/08/2005 Vendor alerted
06/08/2005 First vendor response
06/10/2005 Vendor confirmed the issue
06/22/2005 Vendor gave temporary test patch
08/15/2005 Vendor public advisory
08/23/2005 GomoR public advisory

VI. REFERENCES

BEA05-80.01
http://dev2dev.bea.com/pub/advisory/135

BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/13717

--
^ ___ ___ FreeBSD Network - http://www.GomoR.org/ <-+
| / __ |__/ Systems & Security Engineer |
| \__/ | \ ---[ zsh$ alias psed='perl -pe ' ]--- |
+--> Net::Packet <=> http://search.cpan.org/~gomor/ <--+

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close