WebApp Sec mailing list archives
RE: what does this allow ?
From: "Calderon, Juan C (EM, DDEMESIS)" <Juan.Calderon () ge com>
Date: Thu, 19 Jun 2003 11:32:35 -0400
Hi Vince! I think this article from CERT will help you a lot. It contains description, impact and user solutions to XSS attacks. However the best is to fix the vulnerability at your site, depending of situation you can be exposing your customers to thighs going from disgusting images to sensitive information stealth. http://www.cert.org/advisories/CA-2000-02.html cheers :) -----Original Message----- From: Vince Hoffman [mailto:Vince.Hoffman () uk circle com] Sent: Thursday, June 19, 2003 4:20 AM To: 'webappsec () securityfocus com' Subject: what does this allow ? Hi all, I was running a routine nessus scan on some servers i administrate and one of them gave me a warning of The following requests seem to allow the reading of sensitive files or XSS. You should manually try them to see if anything bad happens : /default.asp?gateway=<script>alert('foo')</script> I tried that and it worked, I forwarded it to a developer for that machine and he didnt seem worried by it. Should he be ? A bit vague i know but webapps arent realy my forte. Thanks, Vince
Current thread:
- what does this allow ? Vince Hoffman (Jun 19)
- Re: what does this allow ? Kevin Spett (Jun 19)
- Re: what does this allow ? Gary H. Jones II (Jun 19)
- <Possible follow-ups>
- Fwd: what does this allow ? Peter Wood (Jun 19)
- RE: what does this allow ? Calderon, Juan C (EM, DDEMESIS) (Jun 19)
- RE: what does this allow ? Vince Hoffman (Jun 19)