W3C Jigsaw Proxy Server Cross-Site Scripting Vulnerability
BID:5506
Info
W3C Jigsaw Proxy Server Cross-Site Scripting Vulnerability
| Bugtraq ID: | 5506 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Aug 19 2002 12:00AM |
| Credit: | Discovered by Hiromitsu Takagi <[email protected]>. |
| Vulnerable: |
W3C Jigsaw 2.2 |
| Not Vulnerable: |
W3C Jigsaw 2.2.1 |
Discussion
W3C Jigsaw Proxy Server Cross-Site Scripting Vulnerability
The W3C Jigsaw project includes a HTTP proxy server written in Java.
When the proxy server cannot successfully resolve a fully qualified domain name, an error page is served to the client. The requested URL is included in the content of this page without being adequately sanitized. Consequently, embedded script code may execute within the context of the requested URL (and it's domain). Exploitation may result in theft of cookie information or impersonation of websites associated with the domain.
The W3C Jigsaw project includes a HTTP proxy server written in Java.
When the proxy server cannot successfully resolve a fully qualified domain name, an error page is served to the client. The requested URL is included in the content of this page without being adequately sanitized. Consequently, embedded script code may execute within the context of the requested URL (and it's domain). Exploitation may result in theft of cookie information or impersonation of websites associated with the domain.
Exploit / POC
W3C Jigsaw Proxy Server Cross-Site Scripting Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
W3C Jigsaw Proxy Server Cross-Site Scripting Vulnerability
Solution:
This vulnerability was eliminated in version 2.2.0.
W3C Jigsaw 2.2
Solution:
This vulnerability was eliminated in version 2.2.0.
W3C Jigsaw 2.2
-
W3C Jigsaw 2.2.1
http://www.w3.org/Jigsaw/#Getting