Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting

Author: Lorenzo Hernandez Garcia-Hierro
type: webapps
platform: php
port: 
date_added: 2003-08-04  
date_updated: 2012-11-29  
verified: 1  
codes: OSVDB-2124  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 22986.txt  
source: https://www.securityfocus.com/bid/8339/info

It is possible to create an authentication or access control page, using Dreamweaver MX PHP Authentication Suite. This script will generate an error page that contains dynamic content when a user fails to authenticate correctly to the site.

A cross-site-scripting vulnerability has been reported to affect PHP authentication functions used in PHP access control pages created with the Macromedia Dreamweaver MX PHP Authentication Suite.

An attacker may exploit this condition to execute arbitrary HTML code in the browser of an unsuspecting user.

http://www.example.com/[PATH]/[LOGIN PAGE].php?[ACCESS DENIED VARIABLE]
="><script>alert('.::\/\|NSRG-18-7|/\/::.');</script>