TCLHttpd 3.4.2 – Multiple Cross-Site Scripting Vulnerabilities

TCLHttpd 3.4.2 – Multiple Cross-Site Scripting Vulnerabilities

漏洞ID 1054188 漏洞类型
发布时间 2003-09-24 更新时间 2003-09-24
图片[1]-TCLHttpd 3.4.2 – Multiple Cross-Site Scripting Vulnerabilities-安全小百科CVE编号 N/A
图片[2]-TCLHttpd 3.4.2 – Multiple Cross-Site Scripting Vulnerabilities-安全小百科CNNVD-ID N/A
漏洞平台 Multiple CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/23174
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8688/info

It has been reported that several of the modules included with TCLHTtpd are vulnerable to cross-site scripting attacks. According to the report, the Status, Debug, Mail and Admin modules are affected by these vulnerabilities. Four instances of this vulnerability have been pointed out, all appearing to be in the Debug module. These vulnerabilities may allow an attacker to execute script code in the context of another client session. Cookie theft and content modification attacks are possible.

The discoverer of this vulnerability has stated that version 3.4.2 is affected. It is likely that prior versions are also vulnerable. 

http://example/debug/echo?name=<script>alert('hello');</script>
http://example/debug/dbg?host=<script>alert('hello');</script>
http://example/debug/showproc?proc=<script>alert('hello');</script>
http://example/debug/errorInfo?title=<script>alert('hello');</script>

相关推荐: OSCommerce Checkout_Confirmation.PHP Comment HTML Injection Vulnerability

OSCommerce Checkout_Confirmation.PHP Comment HTML Injection Vulnerability 漏洞ID 1100691 漏洞类型 Input Validation Error 发布时间 2003-03-20…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享