[25974] in bugtraq

home help back first fref pref prev next nref lref last post

ALERT: Lil'HTTP Server (Summit Computer Networks)

daemon@ATHENA.MIT.EDU (Matthew Murphy)
Thu Jun 27 18:54:33 2002

Message-ID: <001701c21d39$b3624b20$e62d1c41@kc.rr.com>
From: "Matthew Murphy" <mattmurphy@kc.rr.com>
To: "SecurITeam News" <news@securiteam.com>, <bugtraq@securityfocus.com>
Date: Wed, 26 Jun 2002 12:48:37 -0500
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

ALERT: Lil'HTTP Server (Summit Computer Networks)
Vendor Notified: June 26

I have informed Summit of a flaw in its Lil'HTTP
Server.  The vulnerability lies in the "REPORT"
functionality of urlcount.cgi.

The flaw may allow malicious webmasters to
script actions across domains.

Users can protect themselves by removing the
sample file.

"The reason the mainstream is thought
of as a stream is because it is
so shallow."
                     - Author Unknown


home help back first fref pref prev next nref lref last post