Happymall E-Commerce Software Normal_HTML.CGI跨站脚本攻击漏洞

Happymall E-Commerce Software Normal_HTML.CGI跨站脚本攻击漏洞

漏洞ID 1107319 漏洞类型 跨站脚本
发布时间 2003-05-12 更新时间 2005-10-20
图片[1]-Happymall E-Commerce Software Normal_HTML.CGI跨站脚本攻击漏洞-安全小百科CVE编号 CVE-2003-0278
图片[2]-Happymall E-Commerce Software Normal_HTML.CGI跨站脚本攻击漏洞-安全小百科CNNVD-ID CNNVD-200306-096
漏洞平台 CGI CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/22588
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200306-096
|漏洞详情
Happycgi.comHappymall4.3和4.4版本normal_html.cgi存在跨站脚本攻击(XSS)漏洞。远程攻击者借助file参数插入任意web脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/7557/info

IT has been reported that Happymall E-Commerce is prone to cross-site scripting attacks. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, it may be possible for an attacker to execute arbitrary script code within the browser of a legitimate user visiting the site. 

http://www.target.com/shop/normal_html.cgi?file=<script>alert("XSS")</script>
|参考资料

来源:BUGTRAQ
名称:20030512OnemoreflawinHappymall
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=105276130814262&w;=2
来源:XF
名称:happymall-normalhtml-xss(11988)
链接:http://xforce.iss.net/xforce/xfdb/11988
来源:BID
名称:7557
链接:http://www.securityfocus.com/bid/7557

相关推荐: BIND服务拒绝漏洞

BIND服务拒绝漏洞 漏洞ID 1207377 漏洞类型 未知 发布时间 1998-04-08 更新时间 1998-04-08 CVE编号 CVE-1999-0010 CNNVD-ID CNNVD-199804-017 漏洞平台 N/A CVSS评分 5.0 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享