ProjectBB多个远程跨站脚本漏洞

ProjectBB多个远程跨站脚本漏洞

漏洞ID 1108494 漏洞类型 跨站脚本
发布时间 2005-03-02 更新时间 2005-10-20
图片[1]-ProjectBB多个远程跨站脚本漏洞-安全小百科CVE编号 CVE-2005-0650
图片[2]-ProjectBB多个远程跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200505-353
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/25183
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-353
|漏洞详情
ProjectBB0.4.5.1中的多个跨站脚本攻击(XSS)漏洞,允许远程攻击者通过(1)divers.php(一些报告错误地称为”drivers.php”)的pages参数,(2)在搜索功能的文本区域中,选项部分的(3)forumname,(4)sitename或(5)maximumavatarsize,forum部分的(5)newcategory或(6)newforum字段来注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/12709/info

ProjectBB is reportedly affected by multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

As a result of these vulnerabilities, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. 

http://www.example.com/Zip/divers.php?action=liste&liste=&desc=&pages=[XSS]
|参考资料

来源:XF
名称:projectbb-multiple-xss(19556)
链接:http://xforce.iss.net/xforce/xfdb/19556
来源:BID
名称:12709
链接:http://www.securityfocus.com/bid/12709
来源:VUPEN
名称:ADV-2005-0223
链接:http://www.frsirt.com/english/advisories/2005/0223
来源:SECTRACK
名称:1013332
链接:http://securitytracker.com/id?1013332
来源:SECUNIA
名称:14533
链接:http://secunia.com/advisories/14533
来源:BUGTRAQ
名称:20050308faillesdansProjectBBv0.4.5.1
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=111031893610270&w;=2

相关推荐: Micorsoft windows 2000 Sp4 累积更新包 组策略安全设置漏洞

Micorsoft windows 2000 Sp4 累积更新包 组策略安全设置漏洞 漏洞ID 1197691 漏洞类型 未知 发布时间 2005-10-06 更新时间 2005-10-06 CVE编号 CVE-2005-3171 CNNVD-ID CNNVD…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享