Bajie HTTP Server 实例脚本和程序跨站脚本漏洞

Bajie HTTP Server 实例脚本和程序跨站脚本漏洞

漏洞ID 1107516 漏洞类型 跨站脚本
发布时间 2003-10-16 更新时间 2003-12-31
图片[1]-Bajie HTTP Server 实例脚本和程序跨站脚本漏洞-安全小百科CVE编号 CVE-2003-1511
图片[2]-Bajie HTTP Server 实例脚本和程序跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200312-124
漏洞平台 Multiple CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/23257
https://cxsecurity.com/issue/WLB-2007100127
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-124
|漏洞详情
BajieJavaHTTPServer0.95到0.95zxv4版本存在跨站脚本(XSS)漏洞。远程攻击者借助(1)test.txt的字符串查询,(2)custMsg程序的guestName参数,或者(3)CookieExample程序的cookiename参数注入任意web脚本或者HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/8841/info

Demonstration scripts and servlets that are distributed as part of Bajie HTTP Server have been reported prone to multiple cross-site scripting vulnerabilities.

It has been reported that a remote attacker may construct a malicious link containing script and HTML code to any one of the vulnerable demonstration scripts or servlets on the affected server. If this link is followed the code contained therein will be rendered in the browser of the user who followed the link.

http://www.example.com/cgi/bin/test.txt?<script>alert(document.cookie)</script>
POST /servlet/custMsg?guestName=<script>alert("bang")</script> HTTP/1.0
POST /servlet/CookieExample?cookiename=<script>alert("bang")</script>&cookievalue=&cookiepath=
HTTP/1.0
|参考资料

来源:BID
名称:8841
链接:http://www.securityfocus.com/bid/8841
来源:BUGTRAQ
名称:20031016CSSVulnerabilityinBajieHTTPJServer
链接:http://www.securityfocus.com/archive/1/341452
来源:SREASON
名称:3306
链接:http://securityreason.com/securityalert/3306
来源:SECUNIA
名称:10023
链接:http://secunia.com/advisories/10023
来源:www.geocities.com
链接:http://www.geocities.com/gzhangx/websrv/docs/security.html

相关推荐: Majordomo Config-file admin_password Configuration Vulnerability

Majordomo Config-file admin_password Configuration Vulnerability 漏洞ID 1103650 漏洞类型 Configuration Error 发布时间 2000-12-01 更新时间 2000-1…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享