34007 : Microsoft Content Management Server (CMS) Unspecified XSS
Printer | http://osvdb.org/34007 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
5 1385 about 6 years ago about 3 years ago 1 times 100%

Timeline

Disclosure Date
2007-04-10

Description

Microsoft Content Management Server (2001/2002) contains a flaw that allows a remote cross site scripting attack. This flaw exists because unspecified input is not properly sanitized before being returned to users. This vulnerability can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site, leading to a loss of integrity and confidentially

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Solution: Patch / RCS
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Microsoft has released patches, KB924430 for 2001 SP1 and KB924429 for 2002 SP2, to address this vulnerability. It is also possible to correct the flaw by implementing the following workaround:
Setting an MCMS site to Yes-Read Only will disable content authoring and access to that MCMS server entry point from Site Manager

Setting an MCMS site to Yes-Read Only will disable content authoring and access to that MCMS server entry point from Site Manager, but doesn't remove any files from the file system. If you want to use the Site Manager tool to modify settings on a read-only MCMS site, you must first make the site read-write in the Web Server Configuration tool.
Setting an MCMS site to read-only means that you can't use the client-side SDAPI (or Site Manager) to deploy content. On a read-only site, you must use the server-side SDAPI for content deployment API unless you have a separate read-write Web entry point.

To modify the MCMS site to YES-Read Only, follow these steps:

1. Click Start, click Programs, and then select Microsoft Content Management Server.
2. Click Server Configuration Application.
3. Click the Web tab and then select Configure.
4. In the dialog box for the MCMS Web site you wish to configure, select Yes - Read Only.
5. Click OK to save the changes.

Impact of Workaround: Users will no longer be able to author content via MCMS Web Author (you cannot login with edit rights on an MCMS Server) nor via Site Manager.

Products

Microsoft Corporation
Content Management Server
2001
2002

References

Tools & Filters

25026

Credit

CVSSv2 Score

CVSSv2 Base Score = 4.3
Source: nvd.nist.gov | Generated: 2007-04-11 | Disagree?

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_0 Integrity_impact_1 Availability_impact_0

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use