[NEWS] vqServer Demo File Cross-Site Scripting
From: support@securiteam.comDate: 04/22/02
- Previous message: support@securiteam.com: "[NEWS] Xpede Found to Contain Multiple Vulnerabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Mon, 22 Apr 2002 08:50:27 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
vqServer Demo File Cross-Site Scripting
------------------------------------------------------------------------
SUMMARY
<http://www.vqsoft.com/vq/server/> vqServer, a free Java based
implementation of an HTTP server (that also includes extensive support for
Java servlets and CGI scripts), have been found to contain a cross-site
scripting vulnerability in one of its demo CGIs.
DETAILS
Vulnerable systems:
vqServer version 1.9
One of the examples shipped in a default configuration of vqServer contain
multiple cross-site scripting vulnerabilities.