WordPress多个跨站脚本漏洞

WordPress多个跨站脚本漏洞

漏洞ID 1108198 漏洞类型 跨站脚本
发布时间 2004-09-28 更新时间 2005-10-20
图片[1]-WordPress多个跨站脚本漏洞-安全小百科CVE编号 CVE-2004-1559
图片[2]-WordPress多个跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200412-137
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/24646
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-137
|漏洞详情
WordPress1.2版本存在多个跨站脚本(XSS)漏洞。远程攻击者可以借助各种参数注入任意web脚本或HTMl,这些参数包括(1)wp-login.php的redirect_to,text,popupurl或popuptitle参数,(2)admin-header.php的redirect_url参数(3)bookmarklet.php的popuptitle,popupurl,content或post_title参数(4)categories.php的cat_ID参数(5)edit.php的s参数或(6)edit-comments.php的s或mode参数。
|漏洞EXP
source: http://www.securityfocus.com/bid/11268/info
 
It is reported that WordPress is affected by various cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
 
Wordpress 1.2 is reported vulnerable, however, other versions may be affected as well.

/edit-comments.php?s=[XSS]
/edit-comments.php?mode=[XSS]
|参考资料

来源:XF
名称:wordpress-multiple-scripts-xss(17532)
链接:http://xforce.iss.net/xforce/xfdb/17532
来源:BID
名称:11268
链接:http://www.securityfocus.com/bid/11268
来源:SECUNIA
名称:12683
链接:http://secunia.com/advisories/12683
来源:BUGTRAQ
名称:20040927MultipleXSSVulnerabilitiesinWordpress1.2
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109641484723194&w;=2
来源:SECTRACK
名称:1011440
链接:http://securitytracker.com/id?1011440

相关推荐: PrevxHome 绕过安全限制漏洞

PrevxHome 绕过安全限制漏洞 漏洞ID 1200345 漏洞类型 权限许可和访问控制 发布时间 2005-01-10 更新时间 2005-01-10 CVE编号 CVE-2004-1193 CNNVD-ID CNNVD-200501-032 漏洞平台 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享