PerlDiver
   >> Bug Reports
Thread views: 11796

Print Thread
Programmer Administrator
(Administrator)
09/16/05 12:29 PM
XSS Vulnerability [re: bugz]  

Thank you for the notice. An updated version of PerlDiver is here.

For those who have modified PerlDiver, you may correct the issue by adding the following line after my $module = param( 'module' );

$module =~ s/[^A-Za-z0-9:_]/ /g


This vulnerability does not detrimentally affect the server, but a maliciously modified url may sent to unsuspecting users.

Many thanks goes to Steve Christey, the CVE Editor, and Tom at Secunia Research, for better explaining the nature of the issue described by exploitlabs above. And thanks to exploitlabs for finding it.

Nonessential posts regarding this issue have been removed.

Programmer
Scriptsolutions.com

Post Extras Print Post


 
Entire thread
Subject  Posted byPosted on
*XSS Vulnerability  bugz09/15/05 07:49 PM
..XSS Vulnerability  ProgrammerAdministrator09/16/05 12:29 PM
Jump to

 

Domain Name Registration
Register your .com, .net, .org, .biz, .info, and/or .us domain name with NICForce and save more than 50% over the monopoly prices charged by other domain registrars.

¯¯¯¯¯¯¯¯¯
click here!

Managed DNS & Domain Forwarding
Take control of your domain name today! Five minute propagation of changes; Full zone management functionality: Domain forwarding options.

¯¯¯¯¯¯¯¯¯
click here!

E-Mail Hosting
Get your personalized me@mydomain.com e-mail address from $15.95/year. Professional, personalized e-mail services with your own unique domain name without the added cost of web site hosting.

¯¯¯¯¯¯¯¯¯
click here!

Ventrilo VoIP Servers
Save on long distance charges with our live-voice-chat Ventrilo servers! Great for multi-player gaming. Choose from 11 server locations in the U.S., Canada, and Europe.

¯¯¯¯¯¯¯¯¯
click here!

Domain & Web Hosting
True premium web, domain, and e-mail hosting! Generous disk space and bandwidth allocations; Reliable Linux hosting; Web-based control panel; MySQL; PHP; ASP; and much, much more!

¯¯¯¯¯¯¯¯¯
click here!

© 1997-2007, TNS Group, Inc.