ID

VAR-200303-0100


CVE

CVE-2003-0053


TITLE

Apple QuickTime/Darwin Streaming Server Parse_XML.CGI Cross-Site Scripting Vulnerability

Trust: 0.9

sources: BID: 6958 // CNNVD: CNNVD-200303-042

DESCRIPTION

Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message. When an invalid filename is specified from this page, it is output to an error page without sufficient sanitization of HTML and script code. This may permit cross-site scripting attacks to occur if an attacker constructs a malicious link to the page and can entice web users to visit it. Apple Darwin and QuickTime stream management server is a WEB-based service that allows administrators to manage Darwin and QuickTime stream servers. By default, these services listen to port 1220/TCP with ROOT privileges. The parse_xml.cgi of the Darwin/QuickTime streaming server does not sufficiently filter the non-existing file name parameters. If an attacker passes a non-existent file name parameter to the parse_xml.cgi script, the script will generate an error message and record it. If the parameter provided by the attacker contains malicious script code, the administrator can use the Script code is executed on the browser

Trust: 1.26

sources: NVD: CVE-2003-0053 // BID: 6958 // VULHUB: VHN-6883

AFFECTED PRODUCTS

vendor:applemodel:darwin streaming serverscope:eqversion:4.1.2

Trust: 1.9

vendor:applemodel:quicktime streaming serverscope:eqversion:4.1.1

Trust: 1.6

sources: BID: 6958 // CNNVD: CNNVD-200303-042 // NVD: CVE-2003-0053

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-0053
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200303-042
value: MEDIUM

Trust: 0.6

VULHUB: VHN-6883
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2003-0053
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-6883
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-6883 // CNNVD: CNNVD-200303-042 // NVD: CVE-2003-0053

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2003-0053

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200303-042

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200303-042

EXTERNAL IDS

db:NVDid:CVE-2003-0053

Trust: 2.0

db:BIDid:6958

Trust: 2.0

db:CNNVDid:CNNVD-200303-042

Trust: 0.7

db:BUGTRAQid:20030224 QUICKTIME/DARWIN STREAMING ADMINISTRATION SERVER MULTIPLE VULNERABILITIES

Trust: 0.6

db:XFid:11404

Trust: 0.6

db:VULHUBid:VHN-6883

Trust: 0.1

sources: VULHUB: VHN-6883 // BID: 6958 // CNNVD: CNNVD-200303-042 // NVD: CVE-2003-0053

REFERENCES

url:http://www.securityfocus.com/bid/6958

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2003/feb/25/applesa20030225macosx102.txt

Trust: 1.7

url:http://www.iss.net/security_center/static/11404.php

Trust: 1.7

url:http://marc.info/?l=bugtraq&m=104618904330226&w=2

Trust: 1.1

url:http://marc.theaimsgroup.com/?l=bugtraq&m=104618904330226&w=2

Trust: 0.6

url:http://www.info.apple.com/usen/security/security_updates.html

Trust: 0.3

url: -

Trust: 0.1

sources: VULHUB: VHN-6883 // BID: 6958 // CNNVD: CNNVD-200303-042 // NVD: CVE-2003-0053

CREDITS

Dave G.※ daveg@atstake.com※Ollie Whitehouse※ ollie@atstake.com

Trust: 0.6

sources: CNNVD: CNNVD-200303-042

SOURCES

db:VULHUBid:VHN-6883
db:BIDid:6958
db:CNNVDid:CNNVD-200303-042
db:NVDid:CVE-2003-0053

LAST UPDATE DATE

2024-08-14T12:44:10.039000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-6883date:2016-10-18T00:00:00
db:BIDid:6958date:2015-03-19T09:11:00
db:CNNVDid:CNNVD-200303-042date:2005-05-13T00:00:00
db:NVDid:CVE-2003-0053date:2016-10-18T02:28:51.140

SOURCES RELEASE DATE

db:VULHUBid:VHN-6883date:2003-03-07T00:00:00
db:BIDid:6958date:2003-02-24T00:00:00
db:CNNVDid:CNNVD-200303-042date:2003-02-24T00:00:00
db:NVDid:CVE-2003-0053date:2003-03-07T05:00:00