Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
From: Taylor Huff (thuff_at_raytheon.com)
Date: Tue Oct 01 2002 - 10:09:20 CDT
Advisory name: XSS bug in Compaq Insight Manager Http server
Application: Compaq Insight Manager Http server
Impact: XSS code execution
XSS bug in Compaq Insight Manager Http server
The Compaq Insight Manager Http server is vulnerable to the Cross Site
Scripting (XSS) vulnerability. This vulnerability is caused by the
results returned to a user when a non-existing file is requested. The
vulnerability would allow an attacker to make the server present another
executed without the users knowledge (e.g. the result contains the
with a popular open-source vulnerability assessment tool and confirmed
using the following XSS test.
There is a 3rd party software tool that can be used for security
assessments that flags any web server as potentially having this
problem. Our web servers do not, to our knowledge, have this
vulnerability. We have investigated it but it is a non-issue for us.
This issue is just a 'potential vulnerability' rather than a 'for sure'
problem. In other words, the tool is guessing that all web servers can
have this problem.