Location HTTP header injection vulnerabilityOn February 14th, an advisory posted on BugTraq (bugtraq, InfoHacking) described two ways to inject data into HTTP responses using a crafted request.
This article discusses the advisory as it pertains to Zeus Web Server, and assesses how it may be exploited to provoke undesired behaviour. Read more...
Owen Garrett
[Zeus Dev Team] 15 February 2007
Content Negotiation security advisoryZeus has discovered a serious security bug in the Content Negotiation feature of Zeus Web Server in versions prior to 4.3r3. This document describes the scope of the problem and its solution. Read more...
Content Manager
[Administrator] 16 June 2006
Disabling low-grade encryption in ZWS 4.3 and aboveNew security requirements can require that low-grade encryption ciphers are not accepted from clients when they initiate an SSL request to a webserver. In releases of ZWS version 4.3 and above, new features have been added to allow the list of acceptable ciphers to be manually specified.
Content Manager
[Administrator] 14 June 2004
Zeus Web Server Admin Interface Cross Site Scripting VulnerabilityOn the 29th of May 2003, a cross-site-scripting attack against the Zeus Administration Server was reported on bugtraq (incident "Zeus Web Server Admin Interface VS_Diag.CGI Cross Site Scripting Vulnerability").
Content Manager
[Administrator] 30 May 2003
Zeus Web Server Admin Interface Cross Site Scripting VulnerabilityOn November 9th 2002, a cross-site-scripting attack against the Zeus Administration Server was reported on bugtraq (incident "Zeus Web Server Admin Interface Cross Site Scripting Vulnerability").
Content Manager
[Administrator] 21 November 2002
|
Recently...
Other Resources
|

