Cross Site Scripting Vulnerability in DeleGate Proxy Server
A cross-site scripting vulnerability exists in DeleGate Proxy server that results in automatic JavaScript code execution.
Ken Pfeil
January 9, 2002
1 Min Read
Reported January 4, 2002, bySatoshi Ishizuka.
VERSION AFFECTED
DeleGate Proxy Server 7.7.1 and 7.7.0 for Windows
DESCRIPTION
Across-site scripting vulnerability exists in DeleGate Proxy server that resultsin automatic JavaScript code execution on the Web user's browser whenthere's a URL that displays the error message "403 Forbidden" and theadministrator displays his or her own configured error message using the MOUNToption.
VENDOR RESPONSE
Thevendor, Delegate, has released version7.8.0 to correct this concern.
CREDIT
Discovered by Satoshi Ishizukaand Keigo Yamazaki.
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like