Location HTTP header injection vulnerability

On February 14th, an advisory posted on BugTraq (bugtraq, InfoHacking) described two ways to inject data into HTTP responses using a crafted request.

  • The "Error response arbitrary injection" method is not applicable to Zeus Web Server.

  • The "Location HTTP header injection" affects Zeus Web Server. A number of other web servers, including Apache and IIS, can also be provoked in this way.

This article discusses the advisory as it pertains to Zeus Web Server, and assesses how it may be exploited to provoke undesired behaviour. Read more...

Owen Garrett [Zeus Dev Team] 15 February 2007  Permalink  

Content Negotiation security advisory

Zeus has discovered a serious security bug in the Content Negotiation feature of Zeus Web Server in versions prior to 4.3r3.

This document describes the scope of the problem and its solution.

Read more...

Content Manager [Administrator] 16 June 2006  Permalink  

Disabling low-grade encryption in ZWS 4.3 and above

New security requirements can require that low-grade encryption ciphers are not accepted from clients when they initiate an SSL request to a webserver.

In releases of ZWS version 4.3 and above, new features have been added to allow the list of acceptable ciphers to be manually specified.

Read more...

Content Manager [Administrator] 14 June 2004  Permalink  

Zeus Web Server Admin Interface Cross Site Scripting Vulnerability

On the 29th of May 2003, a cross-site-scripting attack against the Zeus Administration Server was reported on bugtraq (incident "Zeus Web Server Admin Interface VS_Diag.CGI Cross Site Scripting Vulnerability").

Read more...

Content Manager [Administrator] 30 May 2003  Permalink  

Zeus Web Server Admin Interface Cross Site Scripting Vulnerability

On November 9th 2002, a cross-site-scripting attack against the Zeus Administration Server was reported on bugtraq (incident "Zeus Web Server Admin Interface Cross Site Scripting Vulnerability").

Read more...

Content Manager [Administrator] 21 November 2002  Permalink  

Download Free Trial

Recent Articles

Other Resources



www.zeus.com