[20881] in bugtraq
Re: Webtrends HTTP Server %20 bug
daemon@ATHENA.MIT.EDU (H D Moore)
Tue Jun 5 22:07:04 2001
X-Qmail-Scanner-Mail-From: hdm@secureaustin.com via webserver
X-Qmail-Scanner-Rcpt-To: kaino3@genie.it BUGTRAQ@SECURITYFOCUS.COM
Content-Type: text/plain;
charset="iso-8859-1"
From: H D Moore <hdm@secureaustin.com>
To: Auriemma Luigi <kaino3@genie.it>, <BUGTRAQ@securityfocus.com>
Date: Mon, 4 Jun 2001 17:19:49 -0500
In-Reply-To: <Pine.WNT.4.33.0106031211050.1496-100000@ect004>
MIME-Version: 1.0
Message-Id: <01060417194900.05909@sliver>
Content-Transfer-Encoding: 8bit
A url-encoded character is NOT a unicode code character..
On Sunday 03 June 2001 05:41 am, Auriemma Luigi wrote:
> The bug is really simple. If the attacker insert an unicode space (%20)