Perlfect Solutions
 

[Perlfect-search] stealing cookies with perlfect

Thomas Springer tspringer@idgcom.de
Tue, 07 Nov 2000 10:43:01 +0100
i'm using perlfect happily, but since mr. Guninski posted a common bug to
bugtraq about a week ago, i'm not too happy anymore:

try a search like 
+FOO -</TITLE><SCRIPT>alert(document.cookie)</SCRIPT>

against any perlfect-site and receive the user's cookies in an alert-window.
easy to exploit e.g. for sites with ecommerce or bulletinboards (ubb & mwf,
to name few that use cookies).

any chances to fix this?

thomas

following Guninski's original Bugtraq-Post (ibm seems to use perlfect too...):

---snip----

>Date: Mon, 30 Oct 2000 17:59:25 +0200
>Reply-To: Georgi Guninski <guninski@GUNINSKI.COM>
>From: Bugtraq List <BUGTRAQ@SECURITYFOCUS.COM>
>Subject: Lame cross site scripting against www.ibm.com
>To: BUGTRAQ@SECURITYFOCUS.COM
>
>I know this is really lame issue but guess more sites suffer from it.
>The search engine at http://www.ibm.com allows cross site scripting.
>Try searching for:
>+IBM -</TITLE><SCRIPT>alert(document.cookie)</SCRIPT>
>or try the following url:
>http://www.ibm.com/Search?q=%2BIBM+-%3C%2FTITLE%3E%3CSCRIPT%3Ealert%28docum
ent.cookie%29%3C%2FSCRIPT%3E&realm=All+of+IBM&v=10&lang=en&cc=us&Go.x=6&Go.y
=14
>
>At least it seems not to allow SSI.
>
>Vendor status:
>IBM was notified at least 4 days ago.
>
>Regards,
>Georgi Guninski
>

 Thomas Springer
    Webmaster 
 IDG Interactive