FuseTalk Forum 4.0 – Multiple Cross-Site Scripting Vulnerabilities

FuseTalk Forum 4.0 – Multiple Cross-Site Scripting Vulnerabilities

漏洞ID 1054714 漏洞类型
发布时间 2004-10-13 更新时间 2004-10-13
图片[1]-FuseTalk Forum 4.0 – Multiple Cross-Site Scripting Vulnerabilities-安全小百科CVE编号 N/A
图片[2]-FuseTalk Forum 4.0 – Multiple Cross-Site Scripting Vulnerabilities-安全小百科CNNVD-ID N/A
漏洞平台 CFM CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/24680
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/11407/info

FuseTalk Forum is reported prone to multiple input validation vulnerabilities. These issues may allow a remote attacker to carry out cross-site scripting attacks. The cause of these issues is insufficient sanitization of user-supplied data.

The first issue is reported to exist because the software echoes unsanitized request data as part of an error page to the origin of the request. This makes it possible for an attacker to a construct a malicious link containing HTML or script code, the attacker-supplied code will be rendered as part of an error message if a target user follows the malicious URI link.

FuseTalk Forum is reported prone to an additional cross-site scripting vulnerability.

The problem presents itself when malicious HTML and script code is sent to the 'tombstone.cfm' script through a URI parameter.

This may allow for theft of cookie-based authentication credentials or other attacks.

www.example.comtombstone.cfm?ProfileID=<script>alert(document.cookie)</script>

相关推荐: Videsh Sanchar Nigam Limited (VSNL)密码泄露

Videsh Sanchar Nigam Limited (VSNL)密码泄露 漏洞ID 1203444 漏洞类型 未知 发布时间 2002-12-31 更新时间 2002-12-31 CVE编号 CVE-2002-1946 CNNVD-ID CNNVD-20…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享