[NT] Lil' HTTP Server "Referer" Cross Site Scripting Vulnerability

From: support@securiteam.com
Date: 04/22/02


From: support@securiteam.com
To: list@securiteam.com
Date: Mon, 22 Apr 2002 10:25:54 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Lil' HTTP Server "Referer" Cross Site Scripting Vulnerability
------------------------------------------------------------------------

SUMMARY

 <http://www.summitcn.com/lilhttp/lildocs.html> Lil' HTTP Server is a
lightweight web server. The server has been found to contain a
vulnerability that would allow an attacker inserting malicious JavaScript
into the Referer tag to cause its execution upon the administrator's
viewing of the log files.

DETAILS

Example:
Issuing the following request:
GET / HTTP/1.0
Referer: <script>alert('vulnerable')</script>

Will cause the administrator to execute arbitrary JavaScript upon his
viewing of the log files. Since they are run in the My Computer zone, they
are executed at high privileges settings.

ADDITIONAL INFORMATION

The information has been provided by <mailto:expert@securiteam.com>
SecurITeam Experts.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NT] 4D DoS and Buffer Overflow Vulnerability (Long HTTP Request)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... a denial of service attack against the remote server. ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [NT] Directory Traversal Exploit in SD Server
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... SD Server is very easy to install, ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [NT] Fastream NETFile FTP/WebServer CSS Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Fastream NETFile Server ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [NT] TinyWeb Server Denial of Service Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability in the product allows remote attackers to cause the server ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • Re: AS2005 x64 vs x86 performance
    ... When you run Profiler against the server do you see any other activity? ... Each execution made one execution unit 100%. ... As soon as the XMLA was executed the queries get answered. ... The disk sys on the xeon srv is a FC SAN where I have an array of 4 FC ...
    (microsoft.public.sqlserver.olap)