IBM Directory Server Web Admin GUI (ldacgi.exe) XSS Vulnerability
3 Dec. 2003
Summary
During the audit of 3rd party product, based on IBM Directory Server, Oliver found a cross site scripting vulnerability on IBM's Directory Server Web Admin GUI. The vulnerability exists due to the fact that ldacgi.exe does not validate the input regarding script code.
Credit:
The information has been provided by Oliver Karow.
Vulnerable systems:
* IBM Directory Server version 4.1
Exploit:
By sending the following URL https://server/ldap/cgi-bin/ldacgi.exe?Action=< script>alert("foo")</script>, it is possible for a 3rd party to insert arbitrary HTML and JavaScript code into IBM's Directory Server Admin web page.
Vendor status:
The vendor has been informed - but no reply has been received within 7 days.