PT-2003-1338 · Apple · Apple Darwin Streaming Administration Server+1

Ollie Whitehouse

·

Publicado

2003-03-07

·

Atualizado

2016-10-18

·

CVE-2003-0053

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Darwin Streaming Administration Server version 4.1.2 QuickTime Streaming Server version 4.1.1
Description A cross-site scripting issue allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message. This occurs in the parse xml.cgi component.
Recommendations For Darwin Streaming Administration Server version 4.1.2, avoid using the filename parameter in the affected API endpoint until the issue is resolved. For QuickTime Streaming Server version 4.1.1, restrict access to the parse xml.cgi component to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0053

Produtos afetados

Apple Darwin Streaming Administration Server
Quicktime Streaming Server