PT-2004-2420 · 04Webserver · 04Webserver

Jérôme Athias

·

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-1512

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions 04WebServer version 1.42
Description A cross-site scripting (XSS) issue exists due to the failure to properly quote script code in the URL within the resulting default error page of Response default.html. This allows remote attackers to execute arbitrary web script or HTML.
Recommendations For version 1.42, ensure that script code in URLs is properly quoted in the default error page to prevent XSS attacks. As a temporary workaround, consider restricting access to the default error page until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1512

Produtos afetados

04Webserver