
|
Title: |
Microsoft Internet Information Services UTF-7 XSS Vulnerability |
|
Date: |
1 October 2006 (Last modified: 3 October 2006) |
|
Author: |
Eiji James Yoshida [ptrs-ejy@bp.iij4u.or.jp] |
|
Vulnerable: |
Internet Information Services |
|
Bugtraq ID: |
|
|
Patch: |
|
|
Overview: |
Using UTF-7 encoded URLs, IIS may return user specified content to the browser. If 'Encoding' is set to 'Auto Select', and Internet Explorer finds a UTF-7 string in the response's body, it will set the charset encoding to UTF-7 automatically, unless a certain charset encoding is already enforced. |
|
Proof of concept: |
http://VulnerableSite/+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-.htw?CiWebHitsFile=/iisstart.asp&CiRestriction='' UTF-7("<") = +ADw-, +ADx-, +ADy-, +ADz- |
|
Vendor status: |
IPA/ISEC
was notified on the 27th December 2005. |
|
Similar vulnerability: |
XSS
vulnerabilities in Google.com |
Copyright(c) 2006 Eiji James Yoshida. All rights reserved