Expect Header Cross-Site Scripting Vulnerability Test
Introduction
Thiago Zaninotti has discovered a vulnerability in the Apache HTTP server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Please use the test below to see an example of how this vulnerability can be exploited and to determine whether or not your site is vulnerable.
Test Case / Demonstration
Please enter the URL of your website in the box below and click the "Test Now" button. This will test whether or not your site is vulnerable.
Please note. This test only works in Internet Explorer 6.x with Flash installed.
Your Site to Test
Example: http://www.your-web-site.com (http:// or https:// must be included)
Your site is vulnerable if a new window opens and a JavaScript alert box appears with a message saying that the site is vulnerable.
Your site is not vulnerable if if you do not experience the above behaviour.
Credits
The test is based on Proof of Concept code by Amit Klein.
What should you do?
Please view the Secunia advisory below for information about how you can fix or mitigate the impact of this vulnerability. Secunia will continuously update the Secunia advisory when more information becomes available.