PHPRank Add.PHP跨站脚本漏洞

PHPRank Add.PHP跨站脚本漏洞

漏洞ID 1107037 漏洞类型 跨站脚本
发布时间 2002-10-10 更新时间 2005-10-20
图片[1]-PHPRank Add.PHP跨站脚本漏洞-安全小百科CVE编号 CVE-2002-1799
图片[2]-PHPRank Add.PHP跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200212-747
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/21933
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-747
|漏洞详情
phpRank1.8版本存在跨站脚本(XSS)漏洞。远程攻击者可以通过(1)add.php中的email参数或(2)banurl参数注入任意web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/5945/info

phpRank is a freely available web site link sharing script. It is available for Unix, Linux, and Microsoft operating systems.

It has been reported that phpRank is vulnerable to cross-site scripting attacks. Under some circumstances, it is possible to force the rendering of arbitrary HTML and script code through the add.php portion of the phpRank package. This could allow the execution of potentially malicious script and HTML in the security context of a vulnerable site. 

http://example.com/phprank/add.php?page=add&spass=1&name=2&siteurl=3&email=%3Cscript%3Ealert(42)%3C/script%3E
|参考资料

来源:BUGTRAQ
名称:20021010MultiplevulnerabilitiesinphpRank
链接:http://archives.neohapsis.com/archives/bugtraq/2002-10/0148.html
来源:BID
名称:5945
链接:http://www.securityfocus.com/bid/5945
来源:XF
名称:phprank-javascript-xss(10336)
链接:http://www.iss.net/security_center/static/10336.php

相关推荐: MetaInfo MetaWeb网络服务器升级,执行,并且读取脚本漏洞

MetaInfo MetaWeb网络服务器升级,执行,并且读取脚本漏洞 漏洞ID 1105365 漏洞类型 未知 发布时间 1998-06-30 更新时间 1999-01-01 CVE编号 CVE-1999-0268 CNNVD-ID CNNVD-199901…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享