Required CVE Record Information
Description
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
References 6 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- http://www.ifrance.com/kitetoua/tuto/5holes1.txt x_transferred
- http://www.acme.com/software/thttpd/#releasenotes x_transferred
- iss.net: thttpd-error-page-css(9029) vdb-entryx_transferred
- securityfocus.com: 4601 vdb-entryx_transferred
- archives.neohapsis.com: 20020417 Smalls holes on 5 products #1 mailing-listx_transferred
- osvdb.org: 5125 vdb-entryx_transferred