Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: RE: what does this allow ?

RE: what does this allow ?

From: Calderon, Juan C (EM, DDEMESIS) <Juan.Calderon_at_ge.com>
Date: Thu, 19 Jun 2003 11:32:35 -0400

Hi Vince!

I think this article from CERT will help you a lot. It contains description, impact and user solutions to XSS attacks. However the best is to fix the vulnerability at your site, depending of situation you can be exposing your customers to thighs going from disgusting images to sensitive information stealth.

http://www.cert.org/advisories/CA-2000-02.html

cheers :)

-----Original Message-----
From: Vince Hoffman [mailto:Vince.Hoffman_at_uk.circle.com]
Sent: Thursday, June 19, 2003 4:20 AM
To: 'webappsec_at_securityfocus.com'
Subject: what does this allow ?

Hi all,
        I was running a routine nessus scan on some servers i administrate
and one of them gave me a warning of

The following requests seem to allow the reading of
sensitive files or XSS. You should manually try them to see if anything bad
happens :
/default.asp?gateway=<script>alert('foo')</script>

I tried that and it worked, I forwarded it to a developer for that machine
and he didnt seem worried by it. Should he be ?
A bit vague i know but webapps arent realy my forte.

Thanks,
Vince
Received on Jun 19 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos