[31131] in bugtraq
ZH2003-24SA (security advisory): ChitChat.NET XSS Vulnerability
daemon@ATHENA.MIT.EDU (G00db0y)
Wed Aug 13 12:40:34 2003
Date: 13 Aug 2003 16:03:33 -0000
Message-ID: <20030813160333.7443.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: G00db0y <G00db0y@zone-h.org>
To: bugtraq@securityfocus.com
ZH2003-24SA (security advisory): ChitChat.NET XSS Vulnerability
Published: 13 august 2003
Released: 13 august 2003
Name: ChitChat.NET
Affected Systems: 2.0
Issue: Remote attackers can inject XSS script
Author: G00db0y@zone-h.org
Vendor: http://clickcess.com/
Description
***********
Zone-h Security Team has discovered a flaw in ChitChat.NET v2.0 (and older
versions?).
"ChitChat.NET is an ASP.NET based discussion forum designed specifically
for SQL Server."
Details
*******
It's possibile to inject XSS script in the Name box and in the Topic Title
box.
For example try this:
Name: <script>alert(Zone-h1)</script>
Email address: test@test.com
Topic title: <script>alert(Zone-h)</script>
Message: www.Zone-h.org
Solution:
*********
The vendor has been contacted and a patch was produced.
Suggestions:
************
Filter the posting procedure.
G00db0y - www.zone-h.org admin
Original advisory here: http://www.zone-h.org/en/advisories/read/id=2882/