Bajie Error Message Cross-Site Scripting Vulnerability
BID:7344
Info
Bajie Error Message Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7344 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2003 12:00AM |
| Updated: | Mar 30 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Luca Ercoli. |
| Vulnerable: |
Bajie Java HTTP Server 0.95 zxe Bajie Java HTTP Server 0.95 zxc |
| Not Vulnerable: |
Bajie Java HTTP Server 0.95 zxe1 |
Discussion
Bajie Error Message Cross-Site Scripting Vulnerability
Bajie HTTP server does not sanitize HTML and script code from error output. Remote attackers could possibly exploit this to construct a malicious link to a vulnerable web server that contains hostile HTML and script code. If this link is followed, the attacker-supplied code could be interpreted in the web browser of the user following the link.
This issue was reported in Bajie versions 0.95zxe and 0.95zxc. Other versions may also be affected.
Bajie HTTP server does not sanitize HTML and script code from error output. Remote attackers could possibly exploit this to construct a malicious link to a vulnerable web server that contains hostile HTML and script code. If this link is followed, the attacker-supplied code could be interpreted in the web browser of the user following the link.
This issue was reported in Bajie versions 0.95zxe and 0.95zxc. Other versions may also be affected.
Exploit / POC
Bajie Error Message Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Bajie Error Message Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Bajie Error Message Cross-Site Scripting Vulnerability
References:
References:
- Bajie HTTP Web Server Homepage (Bajie)