Cross Site Scripting Vulnerability in DeleGate Proxy Server

A cross-site scripting vulnerability exists in DeleGate Proxy server that results in automatic JavaScript code execution.

Ken Pfeil

January 9, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported January 4, 2002, bySatoshi Ishizuka.

VERSION AFFECTED

  • DeleGate Proxy Server 7.7.1 and 7.7.0 for Windows

 

DESCRIPTION
Across-site scripting vulnerability exists in DeleGate Proxy server that resultsin automatic JavaScript code execution on the Web user's browser whenthere's a URL that displays the error message "403 Forbidden" and theadministrator displays his or her own configured error message using the MOUNToption.

 


VENDOR RESPONSE

Thevendor, Delegate, has released version7.8.0 to correct this concern.

 

CREDIT
Discovered by Satoshi Ishizukaand Keigo Yamazaki.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like