20011228 DeleGate Cross Site Scripting Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=100956050432351&w=2 CVE-2001-1202
DeleGate 7.7.1 - Cross-Site Scripting
Record summary
CVE-2001-1202 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDeleGate 7.7.1 - Cross-Site ScriptingExploitDB exploitby SNS ResearchNot analyzed1 file
References
4delegate-proxy-css(7745)vdb entry
http://www.iss.net/security_center/static/7745.php 3749vdb entry
http://www.securityfocus.com/bid/3749 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1202