vqServer is a Windows web server written in Java. It is an innovative product, with support internally for Servlets, and external support for many kinds of CGI, (EXE, Perl, ...) However, some of the examples shipped in a default configuration of vqServer contain multiple cross-site scripting vulnerabilities. In one case, it is possible to create a cookie-based(?) attack that persists forever for a specific IP address. This could be used to attack the target via "Cookie Scripting" bugs in many known browsers. Example: (Requires Perl Interpreter) http://localhost/cgi/vq/demos/respond.pl?