[Full-disclosure] [Fwd: Re: Apache Illegal Request Handling Possible XSS Vulnerability]



oops, missed the CC to list
--- Begin Message --- On Tue, 2007-04-24 at 11:24 +0200, Guasconi Vincent wrote:

<?php
echo htmlentities($_SERVER['REQUEST_METHOD']);
echo htmlentities($_SERVER['SERVER_PROTOCOL']);
?>

Sorry but,
where's the hole? (^-^)

Hole is that you still can pass utf7 through it. htmlentities know
nothing about context encoding.

echo "<script>alert('BEeF');</script>" | iconv -f utf8 -t utf7

+ADw-script+AD4-alert('BEeF')+ADsAPA-/script+AD4



Tõnu

--- End Message ---
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • oops wrong hole new video galleries. Free download
    ... Had she the lips as her swollen pussy oops wrong hole some oops wrong ... a crescendo of orgasms one right after cunt muscles perhaps four oops ... wrong hole Nancy kept her juice flowed three minutes. ...
    (sci.logic)
  • Re: [PATCH 00/20] generic show_mem() v5
    ... So the best approach is to get the short-form fix tested and merged ... [PATCH] fix i386 show_memoops ... a page from the memory hole and oopsing. ...
    (Linux-Kernel)
  • Re: [PATCH 00/20] generic show_mem() v5
    ... I'm getting a pretty regular oops that this series would have fixed. ... [PATCH] fix i386 show_memoops ... I figured it was something to do with PAE, ... a page from the memory hole and oopsing. ...
    (Linux-Kernel)
  • [PATCH 000 of 2] md: bug fixes for 2.6.23-rc
    ... kernels, but probably aren't significant enough for -stable (no oops, ... no data corruption, no security hole). ...
    (Linux-Kernel)
  • Re: Randy Brown vs. Annika1980
    ... Except for that fuckin 6th hole at Trophy Club. ... Oops, I meant "owned him." ...
    (rec.sport.golf)