GoAhead WebServer Error Page Cross Site Scripting Vulnerability
BID:5198
Info
GoAhead WebServer Error Page Cross Site Scripting Vulnerability
| Bugtraq ID: | 5198 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0681 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovery credited to Matt Moore <[email protected]>. |
| Vulnerable: |
GoAhead Software GoAhead Webserver (Windows) 2.1 GoAhead Software GoAhead WebServer 2.1.5 GoAhead Software GoAhead WebServer 2.1.4 GoAhead Software GoAhead WebServer 2.1.3 GoAhead Software GoAhead WebServer 2.1.2 GoAhead Software GoAhead WebServer 2.1.1 GoAhead Software GoAhead WebServer 2.1 |
| Not Vulnerable: |
GoAhead Software GoAhead WebServer 2.1.6 |
Discussion
GoAhead WebServer Error Page Cross Site Scripting Vulnerability
A vulnerability has been reported for GoAhead WebServer 2.1. Reportedly, it is possible for attackers to launch cross site scripting attacks against vulnerable systems.
GoAhead WebServer includes unsanitized requested URLs when displaying a 404 error page. An attacker may be able to trick a user into following a link which includes malicious script code, and executing the attack.
A vulnerability has been reported for GoAhead WebServer 2.1. Reportedly, it is possible for attackers to launch cross site scripting attacks against vulnerable systems.
GoAhead WebServer includes unsanitized requested URLs when displaying a 404 error page. An attacker may be able to trick a user into following a link which includes malicious script code, and executing the attack.
References
GoAhead WebServer Error Page Cross Site Scripting Vulnerability
References:
References:
- GoAhead WebServer Product Homepage (GoAhead Software)