Newtelligence DasBlog请求日志HTML注入漏洞

Newtelligence DasBlog请求日志HTML注入漏洞

漏洞ID 1108157 漏洞类型 跨站脚本
发布时间 2004-09-01 更新时间 2005-10-20
图片[1]-Newtelligence DasBlog请求日志HTML注入漏洞-安全小百科CVE编号 CVE-2004-1657
图片[2]-Newtelligence DasBlog请求日志HTML注入漏洞-安全小百科CNNVD-ID CNNVD-200409-002
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/24424
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200409-002
|漏洞详情
NewtelligenceDasBlog的Activity和EventsViewer存在跨站脚本(XSS)漏洞。远程攻击者借助(1)用户代理或者(2)HTTP头文件来源注入任意web脚本或者HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/11086/info

DasBlog is reportedly susceptible to an HTML injection vulnerability in its request log. This vulnerability is due to a failure of the application to properly sanitize user-supplied input data before using it in the generation of dynamic web pages.

This may allow an attacker to inject malicious HTML and script code into the application. An administrator displaying the 'Activity and Events Viewer' will have the attacker-supplied script code executed within their browser in the context of the vulnerable site. This issue may be leverage to steal cookie based authentication credentials. Other attacks are also possible.

Although this issue reportedly affects versions 1.3 through 1.6 of the affected software. 

GET / HTTP/1.1
User-Agent: <script>alert('xss')</script>
Host: www.example.com
Accept: */*
|参考资料

来源:XF
名称:dasblog-useragent-referer-xss(17174)
链接:http://xforce.iss.net/xforce/xfdb/17174
来源:BID
名称:11086
链接:http://www.securityfocus.com/bid/11086
来源:SECUNIA
名称:12416
链接:http://secunia.com/advisories/12416
来源:BUGTRAQ
名称:20040901Cross-SiteScriptingVulnerabilityinNewtelligenceDasBlog
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109443321830050&w;=2
来源:staff.newtelligence.net
链接:http://staff.newtelligence.net/clemensv/PermaLink.aspx?guid=69bce168-cb09-4f09-8d53-f0b97f11b198

相关推荐: Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability

Open WebMail Logindomain Parameter Cross-Site Scripting Vulnerability 漏洞ID 1097115 漏洞类型 Input Validation Error 发布时间 2005-02-14 更新时…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享