GNU MyProxy跨站脚本漏洞

GNU MyProxy跨站脚本漏洞

漏洞ID 1107786 漏洞类型 跨站脚本
发布时间 2004-03-11 更新时间 2005-10-20
图片[1]-GNU MyProxy跨站脚本漏洞-安全小百科CVE编号 CVE-2003-1199
图片[2]-GNU MyProxy跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200403-050
漏洞平台 Linux CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/23801
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200403-050
|漏洞详情
MyProxy20030629存在跨站脚本漏洞。远程攻击者借助URL注入任意web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/9846/info

It has been reported that GNU MyProxy may be prone to a cross-site scripting vulnerability that may allow a remote attacker to execute HTML or script code in a user's browser. The issue presents itself due to insufficient sanitization of user-supplied data.

Due to the possibility of attacker-specified HTML and script code being rendered in a victim's browser, it is possible to steal cookie-based authentication credentials from that user. Other attacks are possible as well.

GNU MyProxy version 20030629 has been reported to be affected by this issue, however, it is possible that other versions are vulnerable as well.

http://www.example.com/<script>alert("Test")</script>
|参考资料

来源:XF
名称:myproxy-xss(15438)
链接:http://xforce.iss.net/xforce/xfdb/15438
来源:BID
名称:9846
链接:http://www.securityfocus.com/bid/9846
来源:OSVDB
名称:4202
链接:http://www.osvdb.org/4202
来源:SECUNIA
名称:11090
链接:http://secunia.com/advisories/11090
来源:BUGTRAQ
名称:20030311XSSinMyProxy20030629
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107902444305344&w;=2

相关推荐: Microsoft IE临时Internet文件文件夹泄露漏洞

Microsoft IE临时Internet文件文件夹泄露漏洞 漏洞ID 1205514 漏洞类型 其他 发布时间 2001-07-21 更新时间 2005-05-02 CVE编号 CVE-2001-0002 CNNVD-ID CNNVD-200107-151…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享