PT-2003-2456 · Bajie · Bajie Java Http Server
Oliver Karow
·
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-1511
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Bajie Java HTTP Server versions 0.95 through 0.95zxv4
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the query string to "test.txt", the
guestName parameter to the "custMsg" servlet, or the cookiename parameter to the "CookieExample" servlet.Recommendations
For Bajie Java HTTP Server versions 0.95 through 0.95zxv4, consider disabling the "custMsg" and "CookieExample" servlets until a patch is available. Restrict access to "test.txt" to minimize the risk of exploitation. Avoid using the
guestName and cookiename parameters in the affected servlets until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bajie Java Http Server