Overview
The eBay web site contains a cross-site scripting vulnerability.
Description
eBay is a popular auction web site. When an eBay user posts an auction, eBay allows SCRIPT tags to be included in the auction description. This creates a cross-site scripting vulnerability in the eBay website. More information about cross-site scripting is available in CERT Advisory CA-2000-02. |
Impact
An attacker may be able to obtain sensitive data from the eBay web site. As of the publication of this document, attackers are using this vulnerability to redirect auction viewers to phishing sites and to modify the eBay auction page to steal credentials. A wide range of impacts may be possible, including disclosure of passwords, credit card numbers, or other personal information. Likewise, information stored in cookies could be stolen or corrupted. An attacker could also exploit web browser vulnerabilities that require scripting support. |
Solution
We are currently unaware of a practical solution to this problem, however the following workarounds may help mitigate the vulnerability: |
Disable scripting |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.cert.org/advisories/CA-2000-02.html
- http://www.cert.org/tech_tips/malicious_code_FAQ.html
- http://www.us-cert.gov/cas/tips/ST04-014.html
- http://www.us-cert.gov/cas/tips/ST05-010.html
- http://pages.ebay.com/education/spooftutorial/spoof_3.html
- http://pages.ebay.com/help/policies/listing-javascript.html
- http://pages.ebay.com/securitycenter/
- http://news.com.com/2100-7349_3-6056687.html
- http://news.com.com/2100-1017-224622.html
Acknowledgements
Thanks to Dan Plakosh of CERT/CC for reporting this vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | None |
CERT Advisory: | CA-2000-02 |
Severity Metric: | 9.58 |
Date Public: | 1999-04-19 |
Date First Published: | 2006-04-03 |
Date Last Updated: | 2006-05-02 15:04 UTC |
Document Revision: | 20 |