TWiki Cross Site Scripting

2011.09.25
Credit: Mesut Timur
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

Information------------------ Name : XSS vulnerability in TWikiSoftware Versions: TWiki 5.0.2 and below. Vendor Homepage: http://twiki.org/ Vulnerability Type : Cross-Site Scripting Severity : High Researcher : Mesut Timur <mesut [at] mavitunasecurity [dot] com> Advisory Reference : NS-11-006 CVE : CVE-2011-3010 Description----------------------------------- TWiki&#174; is a flexible, powerful, and easy to use enterprise wiki,enterprise collaboration platform, and web application platform. It isa Structured Wiki, typically used to run a project development space,a document management system, a knowledge base, or any other groupwaretool, on an intranet, extranet or the Internet. Details----------------------------------- TTWiki is affected by XSS vulnerabilities in version 5.0.2.Example PoC url is as follows : http://example.com/do/view/Main/Jump?create=on&newtopic=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert%280x0051D1%29%3C/script%3E&template=WebCreateNewTopic&topicparent=3http://example.com/do/view/TWiki/ATasteOfTWiki?'"--></style></script><script>alert(0x002B48)</script> You can read the full article about Cross-Site Scripting vulnerabilities from here: http://www.mavitunasecurity.com/crosssite-scripting-xss/ Solution----------------------------------- Upgrade to the latest TWiki version (5.1.0). Credits----------------------------------- It has been discovered on testing of Netsparker, Web ApplicationSecurity Scanner - http://www.mavitunasecurity.com/netsparker/. References----------------------------------- Vendor Url : http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2011-3010MSL Advisory Link : http://www.mavitunasecurity.com/xss-vulnerability-in-twiki5/Netsparker Advisories : http://www.mavitunasecurity.com/netsparker-advisories/ About Netsparker----------------------------------- Netsparker&#174; can find and report security issues such as SQL Injectionand Cross-site Scripting (XSS) in all web applications regardless ofthe platform and the technology they are built on. Netsparker's uniquedetection and exploitation technique -- Netsparker Advisories, <advisories@mavitunasecurity.com> Homepage, http://www.mavitunasecurity.com/netsparker-advisories/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top