MyWebServer 1.0.2 - Long HTTP Request HTML Injection

EDB-ID:

21710


Author:

D4rkGr3y

Type:

remote


Platform:

Windows

Date:

2002-08-14


source: https://www.securityfocus.com/bid/5470/info

MyWebServer is an application and web server for Microsoft Windows operating systems.

If an oversized HTTP request is received by MyWebServer, some content provided as a URL is included in the page generated. An attacker may construct a malicious URL, and entice a user of the site into following it. Injected content will then be rendered in the context of the vulnerable site.

The consequences of exploitation will be highly dependent on the nature of the hosted site.

This vulnerability has been reported in MyWebServer version 1.0.2. Earlier versions may share this vulnerability, this has not however been confirmed.

http://vuln_host/[223b_of_any_data]<font%20size=50>DEFACED<!--//--