IBM Net.Data db2www错误信息跨站脚本攻击(XSS)漏洞

IBM Net.Data db2www错误信息跨站脚本攻击(XSS)漏洞

漏洞ID 1107660 漏洞类型 跨站脚本
发布时间 2004-01-26 更新时间 2005-10-20
图片[1]-IBM Net.Data db2www错误信息跨站脚本攻击(XSS)漏洞-安全小百科CVE编号 CVE-2004-1442
图片[2]-IBM Net.Data db2www错误信息跨站脚本攻击(XSS)漏洞-安全小百科CNNVD-ID CNNVD-200412-768
漏洞平台 Multiple CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/23598
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-768
|漏洞详情
IBMNet.Data7和7.2版本的db2wwwCGIinterpreter存在存在跨站脚本攻击(XSS)漏洞。远程攻击者可以借助一个未被错误信息如“DTWP001E”正确操作的宏文件名注入任意web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/9488/info

IBM Net.Data is prone to cross-site scripting attacks via error message output. This may permit a remote attack to create a link to a system hosting the software that includes embedded HTML and script code. This hostile code may be rendered in the web browser of a user who follows the malicious link.

Exploitation could permit theft of cookie-based authentication credentials or other attacks. 

http://www.example.com/cgi-bin/db2www/<script>alert(document.domain)</script>/A
|参考资料

来源:US-CERTVulnerabilityNote:VU#DMOA-5VNPEL
名称:http://www.kb.cert.org/vuls/id/DMOA-5VNPEL
链接:http://www.kb.cert.org/vuls/id/DMOA-5VNPEL
来源:US-CERTVulnerabilityNote:VU#197318
名称:VU#197318
链接:http://www.kb.cert.org/vuls/id/197318
来源:XF
名称:ibm-netdata-db2wwwcomponent-xss(14925)
链接:http://xforce.iss.net/xforce/xfdb/14925
来源:BID
名称:9488
链接:http://www.securityfocus.com/bid/9488
来源:SECUNIA
名称:10709
链接:http://secunia.com/advisories/10709/
来源:SECTRACK
名称:1008845
链接:http://www.securitytracker.com/id?1008845
来源:OSVDB
名称:3712
链接:http://www.osvdb.org/3712
来源:secunia.com
链接:http://secunia.com/secunia_research/2004-1/advisory/
来源:VULNWATCH
名称:20040126SecuniaResearch:IBMNet.DataMacroNameCross-SiteScriptingVulnerability
链接:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0019.html

相关推荐: Identix BioLogon Client Biometric Authentication Bypass Vulnerability

Identix BioLogon Client Biometric Authentication Bypass Vulnerability 漏洞ID 1103008 漏洞类型 Design Error 发布时间 2001-08-02 更新时间 2001-08-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享