Multiple Vendor Server Response Filtering Weakness
BID:11655
Info
Multiple Vendor Server Response Filtering Weakness
| Bugtraq ID: | 11655 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2004 12:00AM |
| Updated: | Nov 10 2004 12:00AM |
| Credit: | This issue was disclosed by Obscure [[email protected]]. |
| Vulnerable: |
Washington University wu-ftpd 2.6.2 Washington University wu-ftpd 2.6.2 Washington University wu-ftpd 2.6.1 Washington University wu-ftpd 2.6 .0 Washington University wu-ftpd 2.5 .0 Washington University wu-ftpd 2.4.2 VR17 Washington University wu-ftpd 2.4.2 VR16 Washington University wu-ftpd 2.4.1 Rhino Software Serv-U 3.0 ProFTPD Project ProFTPD 1.2.9 ProFTPD Project ProFTPD 1.2.8 ProFTPD Project ProFTPD 1.2.7 ProFTPD Project ProFTPD 1.2.6 ProFTPD Project ProFTPD 1.2.5 ProFTPD Project ProFTPD 1.2.4 ProFTPD Project ProFTPD 1.2.3 ProFTPD Project ProFTPD 1.2.2 ProFTPD Project ProFTPD 1.2.1 ProFTPD Project ProFTPD 1.2 Ipswitch IMail 6.0.6 Eudora Qpopper 3.1.2 |
| Not Vulnerable: | |
Discussion
Multiple Vendor Server Response Filtering Weakness
It has been reported that multiple vendor's servers are affected by a server response splitting weakness.
An attacker may leverage these issues to have attacker-specified data echoed back to the computer that the request originated from. This may facilitate various attacks including cross-site scripting attacks in Web browsers through concurrent exploitation of the issues outlined in BID 3181 (Multiple Vendor HTML Form Protocol Vulnerability).
It has been reported that multiple vendor's servers are affected by a server response splitting weakness.
An attacker may leverage these issues to have attacker-specified data echoed back to the computer that the request originated from. This may facilitate various attacks including cross-site scripting attacks in Web browsers through concurrent exploitation of the issues outlined in BID 3181 (Multiple Vendor HTML Form Protocol Vulnerability).
Exploit / POC
Multiple Vendor Server Response Filtering Weakness
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Multiple Vendor Server Response Filtering Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor Server Response Filtering Weakness
References:
References:
- [Extended HTML Form Attack] (EyeonSecurity)