QID 150353
Date Published: 2021-09-16
QID 150353: Same Site Scripting
Most of the DNS servers include records of the form localhost. IN A 127.0.0.1 But if by mistake, the administrator misses the trailing dot, the record is not fully qualified. So if the domain is example.com, the queries for localhost.example.com would resolve to 127.0.0.1. Reference: https://seclists.org/bugtraq/2008/Jan/270
The websites in affected domain cannot be securely accessed on multi-user system. The attacker can trick another user on the same system to access websites on affected domain in such a manner as to result in cross site scripting leaking cookies.
Solution
Non fully qualified localhost entries should not be present in the nameserver for domains that host websites with HTTP state management (cookies).
Vendor References
CVEs related to QID 150353
Software Advisories
| Advisory ID | Software | Component | Link |
|---|