|
I tried it... couldn't get it to fail. The URL for the "vendor confirmation" is bogus, and the "attack" just causes a typical 404 error. This is with the original IBM HTTP server, it might fail with the Apache HTTP server. Someone might want to try it. Joe > -----Original Message----- > From: owner-midrange-l@midrange.com > [mailto:owner-midrange-l@midrange.com]On Behalf Of Jim Langston > Sent: Thursday, July 05, 2001 6:04 PM > To: MIDRANGE-L@midrange.com > Subject: WebSphere/VisualAge CSS Vulnerability - Lotus Domino CSS > Vulnerability > > > Couple of possible AS/400 vulnerabilities I thought you should all > be aware of. I have not confirmed these, just saw them in a security > alert newsletter I get periodically. > > > The advisory indicates vendor confirmation. A fix is available at: > http://www-4.ibm.com/software/Webservers/appserv/efix.html > > Source: SecurityFocus Bugtraq > http://archives.neohapsis.com/archives/bugtraq/2001-07/0021.html > > *** {01.27.038} Cross - Lotus Domino CSS vulnerability > > Lotus Domino server version 5.0.6 has been found vulnerable to a > Cross-Site Scripting attack. This potentially allows a malicious e-mail > or Web site to execute active scripting in a user's browser via the > vulnerable Domino site. > > This vulnerability has not been confirmed. > > Source: SecurityFocus Bugtraq > http://archives.neohapsis.com/archives/bugtraq/2001-07/0022.html > > ----------------------------------------------------------------------- > > Become a Security Alert Consensus member! If this e-mail was passed to > you and you would like to begin receiving our security e-mail newsletter > on a weekly basis, we invite you to subscribe today. > http://www.networkcomputing.com/consensus/. > > > -- > > > Regards, > > Jim Langston +--- | This is the Midrange System Mailing List! | To submit a new message, send your mail to MIDRANGE-L@midrange.com. | To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com. | To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com. | Questions should be directed to the list owner/operator: david@midrange.com +---
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.