ALERT: Lil'HTTP Server (Summit Computer Networks)

From: Matthew Murphy (mattmurphy@kc.rr.com)
Date: 06/26/02


From: "Matthew Murphy" <mattmurphy@kc.rr.com>
To: "SecurITeam News" <news@securiteam.com>, <bugtraq@securityfocus.com>
Date: Wed, 26 Jun 2002 12:48:37 -0500

ALERT: Lil'HTTP Server (Summit Computer Networks)
Vendor Notified: June 26

I have informed Summit of a flaw in its Lil'HTTP
Server. The vulnerability lies in the "REPORT"
functionality of urlcount.cgi.

The flaw may allow malicious webmasters to
script actions across domains.

Users can protect themselves by removing the
sample file.

"The reason the mainstream is thought
of as a stream is because it is
so shallow."
                     - Author Unknown



Relevant Pages

  • Re: Server Performance Report - Memory in use - showing No data
    ... Please find below the report I received this morning. ... There still isn't any 'Server Specifications' or 'Memory use' data ... click the Backup snap-in in Server Management, ... Critical Errors in Application Log ...
    (microsoft.public.windows.server.sbs)
  • Re: Erroneous E-mails sent entries in Server Usage Report
    ... One of the sbs2k3Sp1 boxes did previously report outgoing messages correctly in the Usage Report. ... I gave up modifying the default recipient policy years ago and now create my own policy on each server before creating users. ... the information "E-mail sent to external recipients" lists *zero* messages being sent by all users other than Administrator. ... Please check the Message Tracking Center. ...
    (microsoft.public.windows.server.sbs)
  • Re: Server Performance Reports broken
    ... I'll try to reinstall R2 and report back on how that goes. ... we cannot remove WSUS from R2 features directly. ... tries to collect WSUS information and WSUS node still appears in Server ... Step 1: Reinstall monitoring component: ...
    (microsoft.public.windows.server.sbs)
  • Re: Erroneous E-mails sent entries in Server Usage Report
    ... As far as I can recall, this problem was not present on my own server before ... did previously report outgoing messages correctly in the Usage Report. ... I gave up modifying the default recipient policy years ago and now create my ... Please check the Message Tracking Center. ...
    (microsoft.public.windows.server.sbs)
  • Re: Server Usage Report
    ... Server firewall to access the Internet. ... Configure ISA Server for monitoring and reporting. ... The SBS Usage report does not pull data from ISA. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)