thttpd CGI Test Script XSS
Medium Nessus Network Monitor Plugin ID 2126
SynopsisThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.
DescriptionThe remote host is running a vulnerable version of Acme thttpd. It is reported that versions prior 2.06 are prone to a cross-site scripting issue which may permit an attacker to embed hostile HTML and script code in an URL. This code may be rendered by the web browser of an innocent user visiting this crafted URL. This would occur in the security context of the vulnerable web site.
SolutionNo solution is known at this time.