Greenguy's Board


Go Back   Greenguy's Board > Programming & Scripting
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2006-01-25, 11:41 AM   #1
ScannerX
Banned
 
Join Date: Jan 2006
Posts: 8
New Apache Cross site scripting vulnerability

Input passed in the URL isn't properly sanitized before being used by the Web-Access-Log viewer. This can be exploited to execute arbitrary JavaScript code in user's browser session in context of an affected website when a malicious log entry is viewed in Geronimo-admin.
http://issues.apache.org/jira/browse/GERONIMO-1474
ScannerX is offline   Reply With Quote
Old 2006-01-25, 10:00 PM   #2
Ajay
Internet! Is that thing still around?
 
Join Date: Jan 2006
Posts: 1
Thread title is a little misleading....

This is a vulnerability for Geronimo (another project by the Apache team), not the Apache httpd server.

http://geronimo.apache.org/

http://httpd.apache.org
Ajay is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 02:06 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc