Web ChatServer HTML Injection Vulnerability
BID:8383
Info
Web ChatServer HTML Injection Vulnerability
| Bugtraq ID: | 8383 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2003 12:00AM |
| Updated: | Aug 11 2003 12:00AM |
| Credit: | Discovery is credited to "morning_wood" <[email protected]>. |
| Vulnerable: |
Sandsprite.com Web ChatServer |
| Not Vulnerable: | |
Exploit / POC
Web ChatServer HTML Injection Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Web ChatServer HTML Injection Vulnerability
Solution:
The vendor contacted Symantec with the following response:
Chatserver is a skeleton application designed to teach the concept of http chunked transfers to developers. It is not designed for, or capable of production use.
Its own readme states the same concerns declared in this advisory.
There will be no patch released because such is outside of the applications design intent.
Please refer to the applications Readme file for more details.
Solution:
The vendor contacted Symantec with the following response:
Chatserver is a skeleton application designed to teach the concept of http chunked transfers to developers. It is not designed for, or capable of production use.
Its own readme states the same concerns declared in this advisory.
There will be no patch released because such is outside of the applications design intent.
Please refer to the applications Readme file for more details.