MyWebServer 1.0.2 - Long HTTP Request HTML Injection

Related Vulnerabilities: CVE-2002-1453  
Publish Date: 14 Aug 2002
Author: D4rkGr3y
                							

                source: http://www.securityfocus.com/bid/5470/info

MyWebServer is an application and web server for Microsoft Windows operating systems.

If an oversized HTTP request is received by MyWebServer, some content provided as a URL is included in the page generated. An attacker may construct a malicious URL, and entice a user of the site into following it. Injected content will then be rendered in the context of the vulnerable site.

The consequences of exploitation will be highly dependent on the nature of the hosted site.

This vulnerability has been reported in MyWebServer version 1.0.2. Earlier versions may share this vulnerability, this has not however been confirmed.

http://vuln_host/[223b_of_any_data]<font%20size=50>DEFACED<!--//--