Microsoft ISA Server Error Page Cross-Site Scripting Vulnerability
BID:7623
Info
Microsoft ISA Server Error Page Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7623 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2003 12:00AM |
| Updated: | May 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Hugo "Vázquez" "Caramés" <[email protected]>. |
| Vulnerable: |
Microsoft ISA Server 2000 SP1 Microsoft ISA Server 2000 FP1 Microsoft ISA Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft ISA Server Error Page Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been reported for Microsoft ISA Server. The vulnerability exists due to insufficient sanitization of certain HTTP header fields.
Successful exploitation could permit a malicious attacker to cause the execution of hostile HTML and script code in the web client of a user who visits the malicious link. Exploitation could allow for attacks that steal cookie-based authentication credentials.
A cross-site scripting vulnerability has been reported for Microsoft ISA Server. The vulnerability exists due to insufficient sanitization of certain HTTP header fields.
Successful exploitation could permit a malicious attacker to cause the execution of hostile HTML and script code in the web client of a user who visits the malicious link. Exploitation could allow for attacks that steal cookie-based authentication credentials.
Exploit / POC
Microsoft ISA Server Error Page Cross-Site Scripting Vulnerability
There is no exploit code required.
There is no exploit code required.
References
Microsoft ISA Server Error Page Cross-Site Scripting Vulnerability
References:
References: