BibORB多个输入验证漏洞

BibORB多个输入验证漏洞

漏洞ID 1108466 漏洞类型 跨站脚本
发布时间 2005-02-17 更新时间 2005-10-20
图片[1]-BibORB多个输入验证漏洞-安全小百科CVE编号 CVE-2005-0251
图片[2]-BibORB多个输入验证漏洞-安全小百科CNNVD-ID CNNVD-200505-100
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/25118
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-100
|漏洞详情
BibORB1.3.2以及可能较早版本的bibindex.php中存在跨站脚本攻击(XSS)漏洞,允许远程攻击者通过search参数来注入任意的HTML和Web脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/12583/info


BibORB is reported prone to multiple vulnerabilities arising from insufficient sanitization of user-supplied input. These issues can be exploited by a remote attacker to carry out cross-site scripting, HTML injection, SQL injection, directory traversal, and arbitrary file upload attacks.

These vulnerabilities are reported to affect BibORB version 1.3.2 and all previous versions. 

http://www.example.com/biborb/bibindex.php?mode=displaysearch&search=%3Cscript%3Ealert%28%27XSS%27%29%3C%2Fscript%3E&sort=ID
|参考资料

来源:BID
名称:12583
链接:http://www.securityfocus.com/bid/12583
来源:FULLDISC
名称:20050217Advisory:MultipleVulnerabilitiesinBibORB
链接:http://marc.theaimsgroup.com/?l=full-disclosure&m;=110864983905770&w;=2
来源:BUGTRAQ
名称:20050217Advisory:MultipleVulnerabilitiesinBibORB
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110868948719773&w;=2

相关推荐: Microsoft IE远程登录客户端文件覆盖漏洞

Microsoft IE远程登录客户端文件覆盖漏洞 漏洞ID 1106251 漏洞类型 其他 发布时间 2001-03-09 更新时间 2005-05-04 CVE编号 CVE-2001-0150 CNNVD-ID CNNVD-200106-049 漏洞平台 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享