Real Story Group. Make Better Technology Decisions.

Formerly CMS Watch. Here's our story
What Real Independence means. Find Out

  • Schedule a Demo
  • Free Sample
  • Contact
  • Subscriber Login
  • Your cart is empty.
Sign up for our Newsletter
  • Home
  • Evaluation Reports
  • Premium Subscriptions
  • About
  • Blog
  • Buy Now
  • Recent Entries
  • Get Custom Feeds

 

 

 

Thomas Kas Thomas

FatWire XSS vulnerability, and the perils of Web 2.0

20-Nov-2007

Tags: Web Content Management, FatWire Content Server

Andrew Davies of Portcullis Computer Security Ltd reports that an older version of FatWire's Web CMS product, Content Server 6.3.0, exposes cross-site scripting (XSS) vulnerabilities "in multiple locations" in the Web UI, "mainly with the search and advanced search functions." FatWire told Davies that it had already fixed the vulnerability in a patch release.

The vulnerability is of a type where a specially-crafted URL (containing JavaScript) can cause mischief if an unsuspecting user clicks a link containing that URL. Also, just typing something like <script>alert('Hacked!')</script> in a search box will cause a script to execute, reportedly.

Just for kicks, I tried searching for word of the vulnerability on http://developernet.fatwire.com. But the Search box was disabled. Probably wise.

My goal here is not to ding FatWire specifically (and remember, 6.3 is not the latest version of Content Server), but to remind you that, in your quest for customer-facing interactivity, to the extent you turn over dynamic interaction to your Web CMS, you are inheriting their security profile. I think we'll see more of these alerts. Forewarned is forearmed.

Update (29 November): FatWire says that the XSS vulnerability described by Portcullis affects only the administrative search interface, not any UI that can seen by non-admins. A patch is available directly from FatWire.

 

    Now Get the Complete Real Story

    Vendor Evaluations

    Learn the real strengths and weaknesses of major vendors from around the world, in our research stream.

Tweet

close x

Free Sample Request

  Digital and Media Asset Management
  Document Management (ECM)
  Enterprise Collaboration & Social Software
  Enterprise Search
  Portals and Content Integration
  SharePoint Ecosystem
  Web Content Management
 Send me bi-weekly tips and insights from Real Story Group.
Your personal information, including your e-mail address, will be held in the strictest of confidence and will never be shared with anyone.

Subscriber Log In


Remember Me
Forgot password?


Not a subscriber?
Learn about our subscriptions

Research Mentioned in this Post

Vendor Evaluations

 | 

Our Newsletter

Get the Real Story bi-weekly.

Have Questions?

USA & Canada
+1 800 325 6190

UK
+44 (0) 20 3318 1911

International
+1 617 340 6464


All Other Inquiries

Our Customers Say

"The ECM Research provides invaluable insights into ECM functionality, business cases, and more. I can strongly recommend this report to any organisation planning to wade into the ever-changing world of ECM."

James Robertson, Managing Director, Step Two Designs

next More

Real Story Group

Follow us on:  RSS  |  Twitter  |  Facebook  |  YouTube

Evaluation Reports

  • Web Content Management
  • Document Management (ECM)
  • Portals and Content Integration
  • Enterprise Search
  • Digital and Media Asset Management
  • SharePoint Ecosystem
  • Enterprise Collaboration & Social Software

Premium Subscriptions

  • Research Streams
  • Advisory Papers
  • Vendors Evaluated
  • Schedule Analyst Consultation
  • Online Education
  • Configure a Subscription

About Us

  • Our Methodology
  • Our Team
  • Media
  • Customer List
  • Events
  • Consulting
  • Contact Us

Need Help?

  • Talk to an Expert
  • FAQs
  • Customer Support
  • Contact Sales Team
  • Help with your account

Copyright Real Story Group 2001 - 2012. All rights reserved.

  • Contact Us
  • Copyright Policy
  • Privacy Policy
  • Terms of Use

Log In

Remember MeForgot password?

close x
close x

All analyst firms claim to be independent or vendor-neutral. We're different.

Real Independence


Get the real story on commercial and open source tools from a firm that works only for you, the technology customer.

close x

Newsletter Signup

Thank you for signing up for The Real Story Group Newsletter. You will receive our monthly newsletter, plus updates with new information on the technology streams you have expressed interest in below.










Choose the streams that you’d like to receive updates for: