Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:XSS:URL-IMG-XSS

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

IMG tag in URL with Javascript Cross-Side Scripting

Release Date

2004/06/30

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: IMG tag in URL with Javascript Cross-Side Scripting


This signature detects HTML <img> tags in URLs that include Javascript. Because <img> tags should never be present in URLs, the presence of Javascript in such a URL is a clear indication of a Cross-Side Scripting (XSS) attack. XSS attacks are typically Web browser-independent.

Extended Description

The webmail package embedded in Merak Mail Server is reported prone to multiple vulnerabilities. The vulnerabilities reported are: - Multiple cross-site scripting vulnerabilities - An HTML injection vulnerability - A PHP source code disclosure vulnerability - An SQL injection vulnerability These vulnerabilities are reported to exist in versions prior to 7.5.2.

Affected Products

  • Merak Mail Server 7.4.5
  • Merak Webmail Server 5.2.7

References

  • BugTraq: 10966
  • CVE: CVE-2009-1968
  • CVE: CVE-2004-1719
  • URL: http://msdn.microsoft.com/workshop/author/dhtml/httponly_cookies.asp
  • URL: http://www.cgisecurity.com/articles/xss-faq.shtml

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out