Document Title: =============== Bundesregierung Website - Cross Site Scripting Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=346 Release Date: ============= 2011-12-21 Vulnerability Laboratory ID (VL-ID): ==================================== 346 Product & Service Introduction: =============================== Die deutsche Bundesregierung, auch Bundeskabinett genannt, besteht aus dem Bundeskanzler und den Bundesministern. Es ist die Regierung der Bundesrepublik Deutschland und übt damit die Exekutivgewalt auf Bundesebene aus. (Copy of the Vendor Website: http://www.bundesregierung.de) Abstract Advisory Information: ============================== A Vulnerability-Lab researcher discovered a non reflective cross site scripting vulnerability in the government site builder CMS. Vulnerability Disclosure Timeline: ================================== 2011-12-18: Public or Non-Public Disclosure Discovery Status: ================= Published Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ A non reflective cross site scripting vulnerability is detected in the media module of the government site builder. The bug allows an attacker to steal admin and user cookies or build a phishing layer over the page with a prepared link. Vulnerable Module(s): [+] videos.html Vulnerable Param(s): [+] ?page= Important Param(s): [+] &view=coverflow Proof of Concept (PoC): ======================= The vulnerability can be exploited by remote attacker with required user inter action. For demonstration or reproduce ... PoC: "};