Microsoft Help and Support Center - '/sysinfo/sysinfomain.htm' Cross-Site Scripting

EDB-ID:

34126




Platform:

Windows

Date:

2010-06-10


source: https://www.securityfocus.com/bid/40721/info

Help and Support Center is prone to a cross-site scripting weakness because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the privileged zone of the browser of an unsuspecting user.

NOTE: This issue is a weakness because the affected file is only accessible by trusted sources unless other vulnerabilities, such as BID 40725 (Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability) are used to bypass the restrictions. This weakness may then be used to execute script code in the privileged zone of the browser by unauthorized sites.


The following example URI is available:

hcp://system/sysinfo/sysinfomain.htm?svr=<h1>test</h1>