Noah’s Classifieds Index.PHP跨站脚本漏洞

Noah’s Classifieds Index.PHP跨站脚本漏洞

漏洞ID 1109067 漏洞类型 跨站脚本
发布时间 2005-09-14 更新时间 2005-10-20
图片[1]-Noah’s Classifieds Index.PHP跨站脚本漏洞-安全小百科CVE编号 CVE-2005-2980
图片[2]-Noah’s Classifieds Index.PHP跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200509-158
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/26261
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200509-158
|漏洞详情
NoahClassifieds是一个基于PHP,MySQL的高度可定制的分类广告程序,它使用户能够无分类及子分类的限制来投放广告。phpoutsourcingNoah’sclassifieds1.3版本的index.php文件中存在跨站脚本漏洞,允许远程攻击者通过rollid参数注入任意web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/14835/info

Noah's Classifieds is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. 


http://www.example.com/classifieds/index.php?methode=showdetails&list=Advertisment&rollid=4'<script>alert(document.cookie)</script>
|参考资料

来源:XF
名称:noahs-classified-index-xss(22274)
链接:http://xforce.iss.net/xforce/xfdb/22274
来源:BID
名称:14835
链接:http://www.securityfocus.com/bid/14835
来源:SECUNIA
名称:16826
链接:http://secunia.com/advisories/16826/
来源:MISC
链接:http://www.irannetjob.com/index.php?option=com_content&task;=view&id;=122&Itemid;=28
来源:BUGTRAQ
名称:20050914SQLinjection&XSSinphpoutsourcingNoah;’sclassifieds
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112680539610442&w;=2

相关推荐: Veritas Backup Exec Remote Agent for Windows Servers Privilege Escalation Vulnerability

Veritas Backup Exec Remote Agent for Windows Servers Privilege Escalation Vulnerability 漏洞ID 1096426 漏洞类型 Design Error 发布时间 2005-0…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享