PHPKit Include.PHP跨站脚本(XSS)漏洞

PHPKit Include.PHP跨站脚本(XSS)漏洞

漏洞ID 1107565 漏洞类型 跨站脚本
发布时间 2003-11-02 更新时间 2005-10-20
图片[1]-PHPKit Include.PHP跨站脚本(XSS)漏洞-安全小百科CVE编号 CVE-2003-1187
图片[2]-PHPKit Include.PHP跨站脚本(XSS)漏洞-安全小百科CNNVD-ID CNNVD-200311-002
漏洞平台 PHP CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/23333
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200311-002
|漏洞详情
PHPKIT1.6.02和1.6.03版本中的include.php存在跨站脚本(XSS)漏洞。远程攻击者可以通过contact_email参数注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/8960/info

PHPKIT is reported to be prone to a cross-site scripting vulnerability. This is due to insufficient sanitization of HTML from URI parameters, which will be displayed in web pages that are dynamically generated by the software. The issue exists in the 'include.php' script.

An attacker could exploit this issue by enticing a user to follow a malicious link. This could theoretically allow for theft of cookie-based authentication credentials or other attacks. 

http://www.example.com/include.php?path=contact.php&contact_email="><script>alert(123);</script>
|参考资料

来源:XF
名称:phpkit-include-xss(13590)
链接:http://xforce.iss.net/xforce/xfdb/13590
来源:BID
名称:8960
链接:http://www.securityfocus.com/bid/8960
来源:FULLDISC
名称:20031102[bWM#017]Cross-Site-Scripting@PHPKIT
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013139.html
来源:badwebmasters.net
链接:http://badwebmasters.net/advisory/017/

相关推荐: Solaris automount漏洞

Solaris automount漏洞 漏洞ID 1105338 漏洞类型 其他 发布时间 1997-11-26 更新时间 2005-05-02 CVE编号 CVE-1999-0210 CNNVD-ID CNNVD-199711-016 漏洞平台 Solari…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享