Monkey HTTP Server Multiple Cross Site Scripting Vulnerabilities
BID:5829
Info
Monkey HTTP Server Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 5829 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2002 12:00AM |
| Updated: | Sep 30 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to DownBload <[email protected]>. |
| Vulnerable: |
Monkey Monkey HTTP Daemon 0.5 Monkey Monkey HTTP Daemon 0.4.2 Monkey Monkey HTTP Daemon 0.4.1 Monkey Monkey HTTP Daemon 0.4 Monkey Monkey HTTP Daemon 0.1.4 |
| Not Vulnerable: | |
Discussion
Monkey HTTP Server Multiple Cross Site Scripting Vulnerabilities
Monkey HTTP server is prone to cross site scripting vulnerabilities.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link. Attacker-supplied HTML and script code may be executed on a web client visiting the malicious link in the context of the webserver.
Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Monkey HTTP server is prone to cross site scripting vulnerabilities.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link. Attacker-supplied HTML and script code may be executed on a web client visiting the malicious link in the context of the webserver.
Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Exploit / POC
Monkey HTTP Server Multiple Cross Site Scripting Vulnerabilities
The following proof of concepts were provided:
www.victim.com/<script>alert('test');</script>
www.victim.com/cgi-bin/test2.pl?<script>alert('test');</script>
The following proof of concepts were provided:
www.victim.com/<script>alert('test');</script>
www.victim.com/cgi-bin/test2.pl?<script>alert('test');</script>
Solution / Fix
Monkey HTTP Server Multiple Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Monkey HTTP Server Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Monkey HTTP Daemon Product Page (Monkey)