PT-2003-1338 · Apple · Apple Darwin Streaming Administration Server+1
Ollie Whitehouse
·
Publicado
2003-03-07
·
Atualizado
2016-10-18
·
CVE-2003-0053
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Darwin Streaming Administration Server version 4.1.2
QuickTime Streaming Server version 4.1.1
Description
A cross-site scripting issue allows remote attackers to insert arbitrary script via the
filename parameter, which is inserted into an error message. This occurs in the parse xml.cgi component.Recommendations
For Darwin Streaming Administration Server version 4.1.2, avoid using the
filename parameter in the affected API endpoint until the issue is resolved.
For QuickTime Streaming Server version 4.1.1, restrict access to the parse xml.cgi component to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apple Darwin Streaming Administration Server
Quicktime Streaming Server