ACME Labs thttpd Cross-Site Scripting Vulnerability
BID:4601
Info
ACME Labs thttpd Cross-Site Scripting Vulnerability
| Bugtraq ID: | 4601 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2002 12:00AM |
| Updated: | Apr 25 2002 12:00AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
Acme thttpd 2.20 c Acme thttpd 2.20 b |
| Not Vulnerable: | |
Discussion
ACME Labs thttpd Cross-Site Scripting Vulnerability
thttpd is a web server product maintained by ACME Labs. thttpd has been compiled for Linux, BSD and Solaris, as well as other Unix like operating systems.
Cross Site Scripting issues has been reported in some versions of thttpd. thttpd fails to check URLs for the presence of script commands when generating error pages, allowing the attacker-supplied code to execute within the context of the hosted site.
It should be noted that this issue was tested on 2.20b, other versions may also be affected by this issue.
thttpd is a web server product maintained by ACME Labs. thttpd has been compiled for Linux, BSD and Solaris, as well as other Unix like operating systems.
Cross Site Scripting issues has been reported in some versions of thttpd. thttpd fails to check URLs for the presence of script commands when generating error pages, allowing the attacker-supplied code to execute within the context of the hosted site.
It should be noted that this issue was tested on 2.20b, other versions may also be affected by this issue.
Exploit / POC
ACME Labs thttpd Cross-Site Scripting Vulnerability
The following exploit has been provided by frog frog <[email protected]>:
http://www.host.com/<script>[SCRIPT]</script>
The following exploit has been provided by frog frog <[email protected]>:
http://www.host.com/<script>[SCRIPT]</script>
Solution / Fix
ACME Labs thttpd Cross-Site Scripting Vulnerability
Solution:
Conectiva has released a security advisory (CLA-2003:777) which contains fixes to address this issue. Users are advised to upgrade as soon as possible.
Acme thttpd 2.20 c
Solution:
Conectiva has released a security advisory (CLA-2003:777) which contains fixes to address this issue. Users are advised to upgrade as soon as possible.
Acme thttpd 2.20 c
-
Conectiva thttpd-2.24-22871U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/thttpd-2.24-22871U90_1cl.i3 86.rpm -
Conectiva thttpd-htpasswd-2.24-22871U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/thttpd-htpasswd-2.24-22871U 90_1cl.i386.rpm
References
ACME Labs thttpd Cross-Site Scripting Vulnerability
References:
References:
- 5 Holes, Part 1 (frog frog)
- thttpd Homepage (Acme)