Sympa新列表HTML注入漏洞

Sympa新列表HTML注入漏洞

漏洞ID 1108129 漏洞类型 跨站脚本
发布时间 2004-08-21 更新时间 2005-10-20
图片[1]-Sympa新列表HTML注入漏洞-安全小百科CVE编号 CVE-2004-1735
图片[2]-Sympa新列表HTML注入漏洞-安全小百科CNNVD-ID CNNVD-200408-210
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/24389
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200408-210
|漏洞详情
Sympa4.1.x及其早期版本的创建列表选项存在跨站脚本漏洞。远程认证用户借助描述字段注入任意web脚本或者HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/10992/info

An HTML injection vulnerability is reported in Sympa. The problem occurs due to a failure of the application to properly sanitize user-supplied input data.

Unsuspecting users viewing the affected page will have attacker-supplied malicious code interpreted by their browser in the security context of the website hosting Sympa.

Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.

Versions 4.1, and all 4.1.x releases are reported vulnerable to this issue. 

Whatever_you_want<script>alert("Your cookie is " + document.cookie)</script>
|参考资料

来源:XF
名称:sympa-description-xss(17057)
链接:http://xforce.iss.net/xforce/xfdb/17057
来源:BID
名称:10992
链接:http://www.securityfocus.com/bid/10992
来源:SECUNIA
名称:12339
链接:http://secunia.com/advisories/12339
来源:BUGTRAQ
名称:20040820CrossSiteScriptingVulnerabilityinSympa
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109312475207604&w;=2

相关推荐: Linux Kernel Random Poolsize SysCTL Handler Integer Overflow Vulnerability

Linux Kernel Random Poolsize SysCTL Handler Integer Overflow Vulnerability 漏洞ID 1097339 漏洞类型 Boundary Condition Error 发布时间 2005-01…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享