Proxy Web Server XSS

medium Nessus Plugin ID 11634

Synopsis

The remote proxy server is prone to cross-site scripting attacks.

Description

The remote host is running a proxy web server that fails to adequately sanitize request strings of malicious JavaScript. By leveraging this issue, an attacker may be able to cause arbitrary HTML and script code to be executed in a user's browser within the security context of the affected site.

Solution

Contact the vendor for a patch or upgrade.

Plugin Details

Severity: Medium

ID: 11634

File Name: proxy_cross_site_scripting.nasl

Version: 1.19

Type: remote

Family: Web Servers

Published: 5/19/2003

Updated: 7/25/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/14/2003

Reference Information

CVE: CVE-2003-0292

BID: 7596

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990