Re: [us...@httpd] XSS vulnerability in default (debian etch installation)?

2009-03-20 Thread matti matti
Hi, 404 Not FoundNot FoundThe requested URL /alert('test'); was not found on this server. The installation is not default, but only mod_jk, AddDefaultCharset and virtualhosts has been edited. On Fri, Mar 20, 2009 at 9:27 AM, Krist van Besien wrote: > On Thu, Mar 19, 2009 at 9

[us...@httpd] XSS vulnerability in default (debian etch installation)?

2009-03-19 Thread matti matti
Hi, If I do in firefox try: http://hostname/%3CScRipT%20%3Ealert(%27test%27)%3B%3C%2FScRipT%20%3E I get a popup with the text "test", and a: Not Found The requested URL / was not found on this server. I havent got many modules loaded, and added only virtualhosts. This does not work in apache 2