Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11652 | exploit vdb entry patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18033 | vdb entry |
http://marc.info/?l=bugtraq&m=110012542615484&w=2 | mailing list |
http://www.soft3304.net/04WebServer/Security.html | |
http://www.security.org.sg/vuln/04webserver142.html | patch |
http://marc.info/?l=bugtraq&m=110054395311823&w=2 | mailing list |
http://secunia.com/advisories/13159/ | third party advisory vendor advisory |