Short Name |
HTTP:XSS:HTML-SCRIPT-IN-URL-VAR |
---|---|
Severity |
Major |
Recommended |
No |
Category |
HTTP |
Keywords |
HTML Script Tag Embedded in URL Variables |
Release Date |
2003/12/17 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts at cross-site scripting attacks. Attackers can create a malicious Web site that includes HTML embedded in the hyperlinks, which can violate site security settings. A victim that accesses these hyperlinks can allow the attacker to view the victim's Web cookies. Web cookies typically contain sensitive information. This technique is also used by some advertisement company to gather information about people, since the extend of the information gathered cannot be controlled, this behavior is considered by default malicious.
Joomla! CMS is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. Joomla! CMS versions 1.6.3 and prior are vulnerable.