Schneider Electric Kerwin Cross-Site Scripting

by Carol~ Moderator - 5/10/12 10:33 AM

In Reply to: VULNERABILITIES / FIXES - May 10, 2012 by Carol~ Moderator

Schneider Electric Kerwin Cross-Site Scripting Vulnerabilities

Release Date : 2012-05-10

Criticality level : Less critical
Impact : Cross Site Scripting
Where : From remote
Solution Status : Vendor Patch

Software: Kerwin 6.x

Description:
phocean has reported some vulnerabilities in Kerwin, which can be exploited by malicious people to conduct cross-site scripting attacks.

1) Input passed via the "evtvariablename" parameter to kw.dll is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

2) Certain input used for searching and displaying content is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerabilities are reported in versions prior to 6.0.1.

Solution:
Reportedly fixed in version 6.0.1.

Provided and/or discovered by
phocean:

Original Advisory:
http://www.phocean.net/2012/05/08/cve-2012-1990-kerwebkerwin-xss-vulnerabilities.html

http://secunia.com/advisories/49041/