• Home
  • Research
  • What We Offer
  • Who We Are
  • Blog
  • Your cart is empty.
  • Log in
  • Subscribe
  • Contact Us
  • Recent Entries
  • Get Custom Feeds
Team Blog
Free Research Sample
Thomas

FatWire XSS vulnerability, and the perils of Web 2.0

Added By Kas Thomas at 20-Nov-2007 | Twitter: @KasThomas |

Andrew Davies of Portcullis Computer Security Ltd reports that an older version of FatWire's Web CMS product, Content Server 6.3.0, exposes cross-site scripting (XSS) vulnerabilities "in multiple locations" in the Web UI, "mainly with the search and advanced search functions." FatWire told Davies that it had already fixed the vulnerability in a patch release.

The vulnerability is of a type where a specially-crafted URL (containing JavaScript) can cause mischief if an unsuspecting user clicks a link containing that URL. Also, just typing something like <script>alert('Hacked!')</script> in a search box will cause a script to execute, reportedly.

Just for kicks, I tried searching for word of the vulnerability on http://developernet.fatwire.com. But the Search box was disabled. Probably wise.

My goal here is not to ding FatWire specifically (and remember, 6.3 is not the latest version of Content Server), but to remind you that, in your quest for customer-facing interactivity, to the extent you turn over dynamic interaction to your Web CMS, you are inheriting their security profile. I think we'll see more of these alerts. Forewarned is forearmed.

Update (29 November): FatWire says that the XSS vulnerability described by Portcullis affects only the administrative search interface, not any UI that can seen by non-admins. A patch is available directly from FatWire.

 

Categories: Kas Thomas, Web Content Management, Content Server

  • Tweet This Entry

Online Education

Check out our classes and Register Today.

Evaluation Research

Get the real story about vendors and products.

My Research

Remember MeForgot password?

Not a subscriber? Learn about our subscriptions

Categories

Channel

  • Collaboration & Community Software (128)
  • Web Analytics (151)
  • Web Content Management (802)

Analyst

  • Adriaan Bloem (46)
  • Tony Byrne (661)
  • Apoorv Durga (8)
  • Jarrod Gingras (33)
  • Alan Pelz-Sharpe (65)
  • Theresa Regli (36)
  • Kas Thomas (77)

Topics

  • Asia-Pacific Marketplace (3)
  • Building Business Case (142)
  • Cloud Computing (6)
  • E-Discovery (1)
  • European Marketplace (16)
  • Governance (14)
  • Implementation (218)
  • Industry Events (1)
  • Industry Standards (111)
  • Information Architecture (84)
  • Intranets (6)
  • Marketplace at Large (505)
  • Open Source (93)
  • Selecting Technology (548)
  • Services Oriented Architecture (4)
  • Software-as-a-Service (18)
  • Usability (7)
  • Vendor Viability & Financials (129)
  • XML (28)

Industries

  • Finance (2)
  • Government (21)
  • Health Care (2)
  • Higher Ed (7)
  • Legal (1)
  • Manufacturing (2)
  • Pharma (1)
  • Publishing-Media (4)
  • Retail (7)

Dates

  • 2010 (69)
  • 2009 (200)
  • 2008 (223)
  • 2007 (166)
  • 2006 (99)
  • 2005 (104)
  • 2004 (58)
  • 2003 (67)
  • 2002 (67)
  • 2001 (28)

Have Questions?

Sales & Customer Support

+1 800 325 6190 (USA)+44 (0) 20 3318 1911 (UK)+1 617 340 6464 (Int'l)sales@realstorygroup.com support@realstorygroup.com

All other inquiries: info@realstorygroup.com

Copyright, 2001 - 2010, Real Story Group. All rights reserved.

  • Contact Us
  • Copyright Policy
  • Privacy Policy
  • Terms of Use

The Real Story Group

  • CMS Watch
  • Enterprise Information
       Watch
  • SharePoint Watch
  • The Real Story Group

Research

  • Vendor Evaluations
  • Webinars & Advisory Papers
  • Online Education
  • Vendor Lists
  • Free Research Sample
  • Purchase Now

What We Offer

  • Research & Advisory
       Services
  • Frequently Asked Questions
  • Consulting Services
  • Customer Support
  • Contact Sales Team

Who We Are

  • We're Different
  • Our Team
  • Media
  • Customer List
  • Events
  • Contact Us

Get the real story via our bi-weekly newsletter.

Follow us on: RSS twitter

Log In

Remember MeForgot password?