New XSS vuln in echo and echo2 ?

Nicob <[email protected]>
Newsgroups gmane.comp.web.fastcgi.devel
Message-ID <[email protected]>
Hello,

I hope this newgroup is the good one to ask my questions, but please do
not hesitate to redirect me to a better place if I'm wrong.

Apparently, there were some known XSS vulnerabilities in
"/fcgi-bin/echo.exe" and "/fcgi-bin/echo2.exe", as described in [1],
using QUERY_STRING. These vulnerabilities have been correctd but XSS is
still possible in newer versions via SCRIPT_URI/REQUEST_URI.

(tested with "echo" and "echo2" on a Oracle WebCache bundle running Linux)
[1]: http://www.osvdb.org/displayvuln.php?osvdb_id=700


Regards,
Nicob

___________________________________
fastcgi-developers mailing list
http://fastcgi.com/fastcgi-developers/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.