Zeus Web服务器管理界面跨站脚本攻击漏洞

Zeus Web服务器管理界面跨站脚本攻击漏洞

漏洞ID 1107087 漏洞类型 跨站脚本
发布时间 2002-11-08 更新时间 2005-10-20
图片[1]-Zeus Web服务器管理界面跨站脚本攻击漏洞-安全小百科CVE编号 CVE-2002-1785
图片[2]-Zeus Web服务器管理界面跨站脚本攻击漏洞-安全小百科CNNVD-ID CNNVD-200212-839
漏洞平台 CGI CVSS评分 1.9
|漏洞来源
https://www.exploit-db.com/exploits/22000
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-839
|漏洞详情
从ZeusWebServer4.0到4.1r2版本Zeus管理服务器存在跨站脚本攻击(XSS)漏洞。远程认证用户借助index.fcgi的section参数注入任意web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/6144/info

The Zeus Web Server contains a web based administration interface that is vulnerable to cross site scripting attacks.

Due to insufficient sanitization of user-supplied input it is possible for an attacker to construct a malicious link which contains arbitrary HTML and script code, which will be executed in the web client of a user who visits the malicious link. It should be noted that the user must authenticate with the administrative interface for the attack to succeed.

The vendor has stated that cookies are not used to store usernames and passwords. 

http://hostname:9090/apps/web/index.fcgi?servers=&section=<script>alert(document.cookie)</script>
|参考资料

来源:BID
名称:6144
链接:http://www.securityfocus.com/bid/6144
来源:XF
名称:zeus-admin-index-xss(10567)
链接:http://www.iss.net/security_center/static/10567.php
来源:BUGTRAQ
名称:20021211Re:ZeusAdminServerv4.1r2index.fcgiXSSbug
链接:http://online.securityfocus.com/archive/1/302961
来源:BUGTRAQ
名称:20021108ZeusAdminServerv4.1r2index.fcgiXSSbug
链接:http://archives.neohapsis.com/archives/bugtraq/2002-11/0104.html

相关推荐: e107 Website System 0.617 – ‘Forum_viewforum.php’ SQL Injection

e107 Website System 0.617 – ‘Forum_viewforum.php’ SQL Injection 漏洞ID 1055099 漏洞类型 发布时间 2005-05-10 更新时间 2005-05-10 CVE编号 N/A CNNVD-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享