Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: what does this allow ?

From: Calderon, Juan C (EM, DDEMESIS) <Juan.Calderon(at)ge.com>
Date: Thu Jun 19 2003 - 11:32:35 EDT


Hi Vince!

I think this article from CERT will help you a lot. It contains description, impact and user solutions to XSS attacks. However the best is to fix the vulnerability at your site, depending of situation you can be exposing your customers to thighs going from disgusting images to sensitive information stealth.

http://www.cert.org/advisories/CA-2000-02.html

cheers :)

-----Original Message-----
From: Vince Hoffman [mailto:Vince.Hoffman@uk.circle.com] Sent: Thursday, June 19, 2003 4:20 AM
To: 'webappsec@securityfocus.com'
Subject: what does this allow ?

Hi all,

        I was running a routine nessus scan on some servers i administrate and one of them gave me a warning of

The following requests seem to allow the reading of sensitive files or XSS. You should manually try them to see if anything bad happens :
/default.asp?gateway=<script>alert('foo')</script>

Do you need help?X

I tried that and it worked, I forwarded it to a developer for that machine and he didnt seem worried by it. Should he be ? A bit vague i know but webapps arent realy my forte.

Thanks,
Vince Received on Thu Jun 19 12:39:50 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:52 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library