|
|
| |
| A security vulnerability in the way NetCraft handles incoming requests allows attackers to insert JavaScript and HTML code into their existing web page using a Cross-Site Scripting attack (CSS). |
| |
Credit:
The information has been provided by Felipe Moniz.
|
| |
Example:
Modifying the following link:
http://uptime.netcraft.com/up/graph/?mode_u=off&mode_w=on&site=200.184.147.62&submit=Examine
Would allow an attacker to cause NetCraft's web page to paste malicious code.
Vendor response:
The issue has been resolved.
|
|
|
|
|
|
|
|