Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: XSS or HTTP Response Splitting?

XSS or HTTP Response Splitting?

From: Joxean Koret <joxeankoret_at_yahoo.es>
Date: 2 Jan 2005 11:15:40 -0000
('binary' encoding is not supported, stored as-is) Hi!
  
I have been discovered recently various security
issues with the ViewCVS python CGI
(http://www.securityfocus.com/archive/1/385885 )
but I'm not sure if the errors are Cross Site
Scripting Vulnerabilities and/or HTTP Response
Splitting.
  
My question is the following: What is the main
difference
between XSS and HTTP Response
Splitting? May be that HTTP Response
Splitting errors modifies the headers and XSS
modifies document content?
  
Thanks in advance to all... And Happy New Year!
Received on Jan 02 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]