Deerfield VisNetic WebSite跨站脚本攻击漏洞

Deerfield VisNetic WebSite跨站脚本攻击漏洞

漏洞ID 1107132 漏洞类型 跨站脚本
发布时间 2002-12-12 更新时间 2002-12-31
图片[1]-Deerfield VisNetic WebSite跨站脚本攻击漏洞-安全小百科CVE编号 CVE-2002-2246
图片[2]-Deerfield VisNetic WebSite跨站脚本攻击漏洞-安全小百科CNNVD-ID CNNVD-200212-852
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/22083
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-852
|漏洞详情
VisNeticWebsite3.5.15之前版本存在跨站脚本攻击(XSS)漏洞。远程攻击者借助指向不存在页面的HTTP引用头注入任意web脚本或HTML。该漏洞导致注入404错误页面。
|漏洞EXP
source: http://www.securityfocus.com/bid/6369/info

A vulnerability has been discovered in VisNetic Website when generating a 404 page for a non-existent resources. The issue is due to insufficient sanitization of the HTTP 'referer' header. It is possible to cause arbitrary code to be executed within the context of the visited 404 page by embedding script code into the HTTP 'referer' header.

An attacker could exploit this issue to steal cookie-based authentication credentials which could be used to hijack a legitimate users session.

It should be noted that this vulnerability was discovered in VisNetic WebSite 3.5.13.1. It is not yet known whether this issue also affects earlier versions.

GET /NonExistentPage.html HTTP/1.0
Host: TARGET
Accept: */*
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)
Referer: "></a><script>alert('Cross Site Scripting')</script>
|参考资料

来源:BID
名称:6369
链接:http://www.securityfocus.com/bid/6369
来源:XF
名称:visnetic-website-referer-xss(10852)
链接:http://xforce.iss.net/xforce/xfdb/10852
来源:www.deerfield.com
链接:http://www.deerfield.com/products/visnetic_website/
来源:BUGTRAQ
名称:20021212VisNeticWebSiteXSSvulnerabilitythroughHTTPrefererheader
链接:http://archives.neohapsis.com/archives/bugtraq/2002-12/0113.html

相关推荐: BindView HackerShield 1.0/1.1 – HackerShield AgentAdmin Password

BindView HackerShield 1.0/1.1 – HackerShield AgentAdmin Password 漏洞ID 1053416 漏洞类型 发布时间 1999-09-10 更新时间 1999-09-10 CVE编号 N/A CNNVD…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享