Vulnerability Note VU#520707
Microsoft Internet Information Server (IIS) contains cross-site scripting vulnerability in redirect response messages
Overview
Visitors to web sites that use Microsoft IIS and also issue redirect response messages are vulnerable to cross-site scripting attacks.
Description
Cross-site scripting is a form of attack in which an intruder leverages the trust between a victim and a web-site the victim trusts. Quoting from CERT Advisory CA-2001-02: Many Internet web sites overlook the possibility that a client may send malicious data intended to be used only by itself. This is an easy mistake to make. After all, why would a user enter malicious code that only the user will see? In this case, when IIS issues a redirect response message, it includes unsanitized derived from the URL in the resulting error message. If an intruder convinces a victim to follow a link with malicious content in it, he can cause the web server to return a page largely under the control of the intruder. If the victim trusts the web site (specifically if Javascript or other script from that site is permitted to run) the intruder can execute arbitrary script as if it came from the web site. Ironically, if the victim is using Microsoft Internet Explorer (IE), he is not vulnerable to this attack since IE recognizes the redirect response message and displays a message of its own, rather than the resulting HTML generated by the web site. For more information, see Microsoft Security Bulletin MS02-018. IIS is a very popular web server, and any client that has a trust relationship with an IIS web site may be vulnerable if that site issues redirect response messages. |
Impact
For a description of the potential impact, see http://www.cert.org/advisories/CA-2000-02.html#impact. |
Solution
For a description of the range of solutions to this problem, see http://www.cert.org/advisories/CA-2000-02.html#solution. In this instance, web site managers should apply a patch as described in MS02-018. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft | Affected | - | 10 Apr 2002 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.microsoft.com/technet/security/bulletin/MS02-018.asp
- http://www.cert.org/advisories/CA-2000-02.html
Credit
Our thanks to Microsoft Corporation, who described this instance of cross-site scripting problems in MS02-018.
This document was written by Shawn V. Hernan.
Other Information
- CVE IDs: CAN-2002-0075
- Date Public: 10 Apr 2002
- Date First Published: 10 Apr 2002
- Date Last Updated: 10 Apr 2002
- Severity Metric: 15.95
- Document Revision: 3
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.