Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1 May 08 2006 07:01PM
Zaninotti, Thiago (thiago nstalker com)
Folks,

During some specific tests with our upcoming Web App Security Scanner tool,
we have found that Apache would kindly accept HTML injection through
"Expect" header. Originally meant to be a protocol flow control that would
give web client the capacity of sending the HTTP headers for server's...

[ more ]  





 

Privacy Statement
Copyright 2007, SecurityFocus