I checked this on gentoo running lighttpd 1.4.11... Nothing abnormal seen. Just the normal page, or a 404 error. Regards, Bart -----Oorspronkelijk bericht----- Van: bl4ck@xxxxxxxxxxx [mailto:bl4ck@xxxxxxxxxxx] Verzonden: vrijdag 9 februari 2007 22:34 Aan: bugtraq@xxxxxxxxxxxxxxxxx Onderwerp: XSS in lighttpd hey guys .. check out this new xss i just found ;P Vulnerable : lighttpd web : http://www.lighttpd.net XSS : http://127.0.0.1/path/search?q=%22%3E%3Cscript%3Ealert%28%27bl4ck%27%29%3C%2 Fscript%3E Discovered By BLacK ZeRo bL4ck@xxxxxxxxxxx Best regards ,,