13 lines
No EOL
1 KiB
Text
13 lines
No EOL
1 KiB
Text
source: https://www.securityfocus.com/bid/29112/info
|
|
|
|
Microsoft Internet Explorer is prone to a weakness that can facilitate cross-site scripting attacks. The issue occurs because the application fails to sufficiently sanitize user-supplied input when handling UTF-7 charset data received in HTTP responses.
|
|
|
|
Attackers can leverage this weakness to aid in cross-site scripting attacks against unsuspecting users of the application.
|
|
|
|
Reports indicate that all versions of Internet Explorer are affected.
|
|
|
|
Other browsers may also be affected under certain configurations, but this has not been confirmed.
|
|
|
|
NOTE: This BID was originally titled 'Apache HTTP Server 403 Error Cross-Site Scripting Vulnerability'.
|
|
|
|
http://www.example.com/Znl5g3k70ZaBUPYmN5RAGUdkskoprzGI63K4mIj2sqzbX0Kc3Fu7vfthepWhmKvjudPuJTNeK9zw5MaZ1yXJi8RJRRuPe5UahFwOblMXsIPTGh3pVjTLdim3vuTKgdazOG9 idQbIjbnpMEco8Zlo5xNRuCoviPx7x7tYYeOgc8HU46gaecJwnHY7f6GlQB8H6kBFhjoIaHE1SQPhU5VReCz1olPh5jZ%3Cfont%20size=50%3EDEFACED%3C!xc+ADw-script+AD4-alert('xss') +ADw-/script+AD4---//-- |