CGIWrap Cross-Site Scripting Vulnerability
BID:3084
Info
CGIWrap Cross-Site Scripting Vulnerability
| Bugtraq ID: | 3084 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2001 12:00AM |
| Updated: | Jul 22 2001 12:00AM |
| Credit: | This vulnerability was discovered by "TAKAGI, Hiromitsu" <[email protected]> and submitted to BugTraq by the author Nathan Neulinger <[email protected]> on July 22nd, 2001. |
| Vulnerable: |
Nathan Neulinger CGIWrap 3.24 Nathan Neulinger CGIWrap 3.23 Nathan Neulinger CGIWrap 3.22 Nathan Neulinger CGIWrap 3.21 Nathan Neulinger CGIWrap 3.11 Nathan Neulinger CGIWrap 3.6.4 Nathan Neulinger CGIWrap 3.6.3 Nathan Neulinger CGIWrap 3.6.2 Nathan Neulinger CGIWrap 3.6.1 Nathan Neulinger CGIWrap 3.6 Nathan Neulinger CGIWrap 3.5 Nathan Neulinger CGIWrap 3.4 Nathan Neulinger CGIWrap 3.3 Nathan Neulinger CGIWrap 3.2 Nathan Neulinger CGIWrap 3.1 Nathan Neulinger CGIWrap 3.0 Nathan Neulinger CGIWrap 2.7 Nathan Neulinger CGIWrap 2.6 Nathan Neulinger CGIWrap 2.5 Nathan Neulinger CGIWrap 2.4 Nathan Neulinger CGIWrap 2.3 Nathan Neulinger CGIWrap 2.2 Nathan Neulinger CGIWrap 2.1 Nathan Neulinger CGIWrap 2.0 Nathan Neulinger CGIWrap 1.0 |
| Not Vulnerable: |
Nathan Neulinger CGIWrap 3.7 |
Discussion
CGIWrap Cross-Site Scripting Vulnerability
CGIWrap is a free, open-source program for running CGI securely.
CGIWrap does not filter embedded scripting commands from user-supplied input. A web user may submit a malicious link into any form which displays user-supplied input, such as guestbooks, forums, etc. Users clicking on the link will have the malicious scripting commands executed in their browser.
CGIWrap is a free, open-source program for running CGI securely.
CGIWrap does not filter embedded scripting commands from user-supplied input. A web user may submit a malicious link into any form which displays user-supplied input, such as guestbooks, forums, etc. Users clicking on the link will have the malicious scripting commands executed in their browser.
Solution / Fix
CGIWrap Cross-Site Scripting Vulnerability
Solution:
The vendor has released a fixed version which addresses this issue.
Solution:
The vendor has released a fixed version which addresses this issue.