FormMail-Clone – Cross-Site Scripting

FormMail-Clone – Cross-Site Scripting

漏洞ID 1053676 漏洞类型
发布时间 2003-01-09 更新时间 2003-01-09
图片[1]-FormMail-Clone – Cross-Site Scripting-安全小百科CVE编号 N/A
图片[2]-FormMail-Clone – Cross-Site Scripting-安全小百科CNNVD-ID N/A
漏洞平台 CGI CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/22137
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/6570/info

FormMail-clone is allegedly prone to cross-site scripting attacks.

The FormMail-clone script does not sufficiently sanitize HTML tags and script code. As a result, a remote attacker may construct a malicious link to the script which contains arbitrary script code. If this link is visited by a web user, the attacker-supplied script code may be interpreted by their browser in the context of the site hosting the software.

This vulnerability was originally reported in FormMail. Additional reports have indicated that the issue actually exists in FormMail-clone, which is an entirely different program which is designed to perform the same function as FormMail but contains none of the original code.

http://www.example.com/cgi-sys/FormMail.cgi?<script>alert("test");</script>

相关推荐: Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability

Computer Associates eTrust Antivirus EE Privilege Escalation Vulnerability 漏洞ID 1101320 漏洞类型 Input Validation Error 发布时间 2002-11-1…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享