PT-2003-2456 · Bajie · Bajie Java Http Server
Oliver Karow
·
Publicado
2003-12-31
·
Atualizado
2008-09-05
·
CVE-2003-1511
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Bajie Java HTTP Server versions 0.95 through 0.95zxv4
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the query string to "test.txt", the
guestName parameter to the "custMsg" servlet, or the cookiename parameter to the "CookieExample" servlet.Recommendations
For Bajie Java HTTP Server versions 0.95 through 0.95zxv4, consider disabling the "custMsg" and "CookieExample" servlets until a patch is available. Restrict access to "test.txt" to minimize the risk of exploitation. Avoid using the
guestName and cookiename parameters in the affected servlets until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bajie Java Http Server