Phorum Search脚本跨站脚本漏洞

Phorum Search脚本跨站脚本漏洞

漏洞ID 1108085 漏洞类型 跨站脚本
发布时间 2004-07-28 更新时间 2005-10-20
图片[1]-Phorum Search脚本跨站脚本漏洞-安全小百科CVE编号 CVE-2004-2242
图片[2]-Phorum Search脚本跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200412-880
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/24331
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-880
|漏洞详情
Phorum5.0.7测试版及其早期版本的search.php可能存在跨站脚本(XSS)漏洞。远程攻击者可以借助subject参数注入任意HTML或web脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/10822/info

A cross-site scripting vulnerability is reported to affect Phorum. This issue affects the 'search.php' script. As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user.

This vulnerability was reported to affect Phorum 5.0.7 beta.

http://www.example.com/phorum5/search.php?12,search=vamp,page=1,match_type=ALL,
match_dates=00,match_forum=ALL ,body=,author=,subject= [ Evil Code Here ]
|参考资料

来源:XF
名称:phorum-searchphp-xss(16831)
链接:http://xforce.iss.net/xforce/xfdb/16831
来源:BID
名称:10822
链接:http://www.securityfocus.com/bid/10822
来源:SECTRACK
名称:1010787
链接:http://securitytracker.com/id?1010787
来源:phorum.org
链接:http://phorum.org/cvs-changelog-5.txt

相关推荐: Sun Solaris libgss Unspecified Privilege Escalation Vulnerability

Sun Solaris libgss Unspecified Privilege Escalation Vulnerability 漏洞ID 1096920 漏洞类型 Design Error 发布时间 2005-04-15 更新时间 2005-04-15 C…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享