FYI…

- http://secunia.com/advisories/23186/
Release Date: 2006-12-04
Critical: Less critical
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Where: From remote
Solution Status: Vendor Patch
Software: Sun Java System Application Server (Sun ONE) 7.x, Sun Java System Application Server 8.x, Sun Java System Web Proxy Server 3.x, Sun Java System Web Proxy Server 4.x, Sun Java System Web Server (Sun ONE/iPlanet) 6.x
Solution: Apply service packs and patches…
Original Advisory: http://sunsolve.sun.com/search/document.do…y=1-26-102733-1 …"
"…Impact:
If the Sun Java System Proxy Server is used in conjunction with the Sun Java System Application Server or the Sun Java System Web Server then it may be susceptible to "HTTP Request Smuggling" (HRS) which can allow remote unprivileged users to be able to poison web caches, hijack sessions, perform cross-site scripting (CSS or XSS) attacks or bypass web application firewall protection…"

:ph34r: