PT-2003-2456 · Bajie · Bajie Java Http Server

Oliver Karow

·

Publicado

2003-12-31

·

Atualizado

2008-09-05

·

CVE-2003-1511

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bajie Java HTTP Server versions 0.95 through 0.95zxv4
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the query string to "test.txt", the guestName parameter to the "custMsg" servlet, or the cookiename parameter to the "CookieExample" servlet.
Recommendations For Bajie Java HTTP Server versions 0.95 through 0.95zxv4, consider disabling the "custMsg" and "CookieExample" servlets until a patch is available. Restrict access to "test.txt" to minimize the risk of exploitation. Avoid using the guestName and cookiename parameters in the affected servlets until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-1511

Produtos afetados

Bajie Java Http Server