New XSS vuln in echo and echo2 ?
Nicob <[email protected]>
| Newsgroups | gmane.comp.web.fastcgi.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello, I hope this newgroup is the good one to ask my questions, but please do not hesitate to redirect me to a better place if I'm wrong. Apparently, there were some known XSS vulnerabilities in "/fcgi-bin/echo.exe" and "/fcgi-bin/echo2.exe", as described in [1], using QUERY_STRING. These vulnerabilities have been correctd but XSS is still possible in newer versions via SCRIPT_URI/REQUEST_URI. (tested with "echo" and "echo2" on a Oracle WebCache bundle running Linux) [1]: http://www.osvdb.org/displayvuln.php?osvdb_id=700 Regards, Nicob ___________________________________ fastcgi-developers mailing list http://fastcgi.com/fastcgi-developers/