PT-2003-1338 · Apple · Apple Darwin Streaming Administration Server+1
Ollie Whitehouse
·
Published
2003-03-07
·
Updated
2016-10-18
·
CVE-2003-0053
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Darwin Streaming Administration Server version 4.1.2
QuickTime Streaming Server version 4.1.1
Description
A cross-site scripting issue allows remote attackers to insert arbitrary script via the
filename parameter, which is inserted into an error message. This occurs in the parse xml.cgi component.Recommendations
For Darwin Streaming Administration Server version 4.1.2, avoid using the
filename parameter in the affected API endpoint until the issue is resolved.
For QuickTime Streaming Server version 4.1.1, restrict access to the parse xml.cgi component to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Darwin Streaming Administration Server
Quicktime Streaming Server