Mambo Site Server index.php跨站脚本攻击(XSS)漏洞

Mambo Site Server index.php跨站脚本攻击(XSS)漏洞

漏洞ID 1107246 漏洞类型 跨站脚本
发布时间 2003-03-18 更新时间 2005-10-20
图片[1]-Mambo Site Server index.php跨站脚本攻击(XSS)漏洞-安全小百科CVE编号 CVE-2003-1203
图片[2]-Mambo Site Server index.php跨站脚本攻击(XSS)漏洞-安全小百科CNNVD-ID CNNVD-200303-047
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/22382
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200303-047
|漏洞详情
MamboSiteServer4.0.10的index.php存在跨站脚本攻击(XSS)漏洞。远程攻击者可以借助?option参数在其他客户端执行脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/7135/info

Mambo Site Server has been reported prone to a cross-site scripting vulnerability.

It has been reported that certain user supplied URI parameters are not sufficiently sanitized by the Mambo Site Server. As a result of this deficiency an attacker may create a specially crafted URL that includes malicious HTML code passed to the index page used by Mambo Site server. 

This may allow for theft of cookie-based authentication credentials and other attacks.

This vulnerability was reported to affect Mambo Site Server version 4.0.10 it is not currently known if other versions are affected.

http://www.example.com/index.php?option=search&searchword=<script>alert(document.cookie);</script>
|参考资料

来源:XF
名称:mambo-option-index-xss(11601)
链接:http://xforce.iss.net/xforce/xfdb/11601
来源:BID
名称:7135
链接:http://www.securityfocus.com/bid/7135
来源:BUGTRAQ
名称:20030318SomeXSSvulns
链接:http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html

相关推荐: RealNetworks RealOne Player And RealPlayer ShowPreferences Action Buffer Overflow Vulnerability

RealNetworks RealOne Player And RealPlayer ShowPreferences Action Buffer Overflow Vulnerability 漏洞ID 1097194 漏洞类型 Boundary Conditi…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享