Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders. This vulnerability is limited to server configurations with Wildcard DNS enabled.
Publication date: Tue, 31 Dec 2002 11:00:00 +0000