Portcullis Security Advisory 07_010 Vulnerable System: SAP Internet Transaction Server Vulnerability Title: Re-introduction of Cross-site Scripting/Cookie Theft Vulnerability. Previous vendor Information: Originally vendor contacted on 02.08.2003 Product: ITS, Version 6.20 Bugtraq ID: 8517 CVE: CAN-2003-0749 Vulnerability Discovery and Development: Portcullis Security Testing Services Credit for Discovery Andrew Davies of Portcullis Computer Security Ltd discovered this vulnerability. Affected systems: Version 6200.1017.50954.0, Build 730827 (win32/IIS 5.0) Details: Object: wgate.dll (win32 CGI-Communication Binary) Description: Insufficient input and output validation on miscellaneous userinput-parameters enables insertion of html/client side scripting tags. Example: HTTP-Requests: http://example.com/scripts/wgate.dll?~service=-->