CGI.Referer.XSS

description-logoDescription

This threat sends a crafted HTTP Request with the referrer field containing a double quote ". This double quote is escaped in C fashion when displayed on a page, allowing an event handle to be created inside of the hyperlink.

affected-products-logoAffected Products

Any HTP server.

Impact logoImpact

Cross site scripting.

recomended-action-logoRecommended Actions

N/A

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-12-11 16.978