Formerly CMS Watch. Here's our story
What Real Independence means. Find Out
Kas Thomas
20-Nov-2007
Tags: Web Content Management, FatWire Content Server
Andrew Davies of Portcullis Computer Security Ltd reports that an older version of FatWire's Web CMS product, Content Server 6.3.0, exposes cross-site scripting (XSS) vulnerabilities "in multiple locations" in the Web UI, "mainly with the search and advanced search functions." FatWire told Davies that it had already fixed the vulnerability in a patch release.
The vulnerability is of a type where a specially-crafted URL (containing JavaScript) can cause mischief if an unsuspecting user clicks a link containing that URL. Also, just typing something like <script>alert('Hacked!')</script> in a search box will cause a script to execute, reportedly.
Just for kicks, I tried searching for word of the vulnerability on http://developernet.fatwire.com. But the Search box was disabled. Probably wise.
My goal here is not to ding FatWire specifically (and remember, 6.3 is not the latest version of Content Server), but to remind you that, in your quest for customer-facing interactivity, to the extent you turn over dynamic interaction to your Web CMS, you are inheriting their security profile. I think we'll see more of these alerts. Forewarned is forearmed.
Update (29 November): FatWire says that the XSS vulnerability described by Portcullis affects only the administrative search interface, not any UI that can seen by non-admins. A patch is available directly from FatWire.
Get the Real Story bi-weekly.
USA & Canada
+1 800 325 6190
UK
+44 (0) 20 3318 1911
International
+1 617 340 6464
All Other Inquiries
"The ECM Research provides invaluable insights into ECM functionality, business cases, and more. I can strongly recommend this report to any organisation planning to wade into the ever-changing world of ECM."
James Robertson, Managing Director, Step Two Designs
Copyright Real Story Group 2001 - 2012. All rights reserved.
All analyst firms claim to be independent or vendor-neutral. We're different.
Get the real story on commercial and open source tools from a firm that works only for you, the technology customer.
Thank you for signing up for The Real Story Group Newsletter. You will receive our monthly newsletter, plus updates with new information on the technology streams you have expressed interest in below.