[bug #32929] Some XSS vulnerabilities in HTTP mldonkey server

Me and I <[email protected]> Sun, 27 Mar 2011 15:23:58 +0000
Newsgroups gmane.network.mldonkey.bugs
Message-ID <[email protected]>
URL:
  <http://savannah.nongnu.org/bugs/?32929>

                 Summary: Some XSS vulnerabilities in HTTP mldonkey server
                 Project: mldonkey, a multi-networks file-sharing client
            Submitted by: mldonkeyuser777
            Submitted on: dom 27 mar 2011 15:23:58 GMT
                Category: HTTP interface
                Severity: 3 - Normal
              Item Group: None
                  Status: None
             Assigned to: None
             Open/Closed: Open
         Discussion Lock: Any
                 Release: 3.0.5
                 Release: 3.0.5
        Operating System: Linux
         Binaries Origin: Gentoo ebuild
                CPU type: Intel x86

    _______________________________________________________

Details:

Hi, I just was testing my localhost with openvas and it launched nikto over
mldonkey webserver in port 4080, I do not know really about if it a false
warning or not.

this is a gentoo box:

Linux 2.6.38 #1 SMP Sun Mar 20 XX:54:51 CET 2011 i686 Intel(R) Pentium(R) 4
CPU 3.00GHz GenuineIntel GNU/Linux

net-p2p/mldonkey
      Latest version available: 3.0.5
      Latest version installed: 3.0.5
      Size of files: 2,715 kB

Log is attached.





    _______________________________________________________

File Attachments:


-------------------------------------------------------
Date: dom 27 mar 2011 15:23:58 GMT  Name: openvasd-nikto_mldonkey_LOG.txt 
Size: 39kB   By: mldonkeyuser777
openvasd/nikto over mldonkey webserver logs
<http://savannah.nongnu.org/bugs/download.php?file_id=23027>

    _______________________________________________________

Reply to this item at:

  <http://savannah.nongnu.org/bugs/?32929>

_______________________________________________
  Mensaje enviado vía/por Savannah
  http://savannah.nongnu.org/