Mewsoft NetAuction跨站脚本漏洞

Mewsoft NetAuction跨站脚本漏洞

漏洞ID 1106796 漏洞类型 跨站脚本
发布时间 2002-06-14 更新时间 2005-10-20
图片[1]-Mewsoft NetAuction跨站脚本漏洞-安全小百科CVE编号 CVE-2002-1703
图片[2]-Mewsoft NetAuction跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200212-526
漏洞平台 CGI CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/21553
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-526
|漏洞详情
MewsoftNetAuction3.0版本的auction.cgi存在跨站脚本(XSS)漏洞。远程攻击者可以借助Term参数作为其他用户执行任意脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/5023/info

NetAuction does not filter HTML code from URI parameters, making it prone to cross-site scripting attacks. Attacker-supplied HTML code may be included in a malicious links. The attacker-supplied HTML code will be executed in the browser of a web user who visits this link, in the security context of the host running NetAuction. Such a link might be included in a HTML e-mail or on a malicious webpage.

http://www.xxxx.com/cgi-bin/auction/auction.cgi?action=Sort_Page&View=Search
&Page=0&Cat_ID=&Lang=English&Search=All&Terms=<script>alert('OopS');</script>&
Where=&Sort=Photo&Dir=
|参考资料

来源:XF
名称:netauction-parameters-css(9365)
链接:http://xforce.iss.net/xforce/xfdb/9365
来源:BID
名称:5023
链接:http://www.securityfocus.com/bid/5023

相关推荐: OmniHTTPD示例脚本远程跨站脚本执行漏洞

OmniHTTPD示例脚本远程跨站脚本执行漏洞 漏洞ID 1106946 漏洞类型 未知 发布时间 2002-08-26 更新时间 2003-06-09 CVE编号 CVE-2002-1455 CNNVD-ID CNNVD-200306-005 漏洞平台 Wi…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享