Inktomi Traffic Server Cross-Site Scripting Vulnerability
BID:7596
Info
Inktomi Traffic Server Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7596 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2003 12:00AM |
| Updated: | May 14 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Hugo Vázquez Caramés & Toni Cortés Martínez. |
| Vulnerable: |
Inktomi Traffic Server 5.2.2 Inktomi Traffic Server 5.2.1 Inktomi Traffic Server 5.2 .0-R Inktomi Traffic Server 5.1.3 Inktomi Traffic Server 4.0.20 Inktomi Traffic Server 4.0.18 |
| Not Vulnerable: | |
Discussion
Inktomi Traffic Server Cross-Site Scripting Vulnerability
Inktomi Traffic Server is prone to a cross-site scripting vulnerability. This is due to insufficient sanitization of input passed to the proxy, which will be echoed back in error pages under some circumstances. A malicious attacker could exploit this issue by creating a link which contains hostile HTML and script code and then enticing users of the proxy to visit the link. When the link is visited via the proxy, attacker-supplied script may be interpreted in the user's browser.
Exploitation could permit HTML and script code to access properties of the domain that is requested through the proxy.
Inktomi Traffic Server is prone to a cross-site scripting vulnerability. This is due to insufficient sanitization of input passed to the proxy, which will be echoed back in error pages under some circumstances. A malicious attacker could exploit this issue by creating a link which contains hostile HTML and script code and then enticing users of the proxy to visit the link. When the link is visited via the proxy, attacker-supplied script may be interpreted in the user's browser.
Exploitation could permit HTML and script code to access properties of the domain that is requested through the proxy.
References
Inktomi Traffic Server Cross-Site Scripting Vulnerability
References:
References:
- Inktomi Homepage (Inktomi)
- Inktomi Traffic-Server XSS: man-in-the-middle XSS ! (Hugo "Vázquez" "Caramés"
)