PT-2003-2456 · Bajie · Bajie Java Http Server

Oliver Karow

·

Published

2003-12-31

·

Updated

2008-09-05

·

CVE-2003-1511

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bajie Java HTTP Server versions 0.95 through 0.95zxv4
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the query string to "test.txt", the guestName parameter to the "custMsg" servlet, or the cookiename parameter to the "CookieExample" servlet.
Recommendations For Bajie Java HTTP Server versions 0.95 through 0.95zxv4, consider disabling the "custMsg" and "CookieExample" servlets until a patch is available. Restrict access to "test.txt" to minimize the risk of exploitation. Avoid using the guestName and cookiename parameters in the affected servlets until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1511

Affected Products

Bajie Java Http Server