CodeToSell ViArt Shop Enterprise多个跨站脚本攻击和HTML注入漏洞。

CodeToSell ViArt Shop Enterprise多个跨站脚本攻击和HTML注入漏洞。

漏洞ID 1108739 漏洞类型 跨站脚本
发布时间 2005-05-02 更新时间 2005-10-20
图片[1]-CodeToSell ViArt Shop Enterprise多个跨站脚本攻击和HTML注入漏洞。-安全小百科CVE编号 CVE-2005-1440
图片[2]-CodeToSell ViArt Shop Enterprise多个跨站脚本攻击和HTML注入漏洞。-安全小百科CNNVD-ID CNNVD-200505-888
漏洞平台 PHP CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/25580
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-888
|漏洞详情
ViArtShopEnterprise2.1.6存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可以通过(1)传给basket.php的各个参数,(2)在forum.php中的昵称、电子邮件、主题和消息字段,如使用forum_new_thread.php和forum_thread.php,(3)传给page.php的page参数,(4)传给review.php的category_id和item_id参数,(5)传给product_details.php的category_id参数,(6)传给product.php的category_id或search_string参数,或(7)传给news_view.php的rp或page参数,注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/13462/info
     
ViArt Shop is affected by multiple cross-site scripting and HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
     
Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
     
These issues are reported to affect ViArt Shop Enterprise version 2.1.6; other versions may also be vulnerable. 

http://www.example.com/news_view.php?news_id=3&rp=news.php[XSS-CODE]&page=1
http://www.example.com/news_view.php?news_id=3&rp=news.php&page=1[XSS-CODE]
|参考资料

来源:BID
名称:13462
链接:http://www.securityfocus.com/bid/13462
来源:OSVDB
名称:15958
链接:http://www.osvdb.org/15958
来源:OSVDB
名称:15957
链接:http://www.osvdb.org/15957
来源:OSVDB
名称:15956
链接:http://www.osvdb.org/15956
来源:OSVDB
名称:15955
链接:http://www.osvdb.org/15955
来源:OSVDB
名称:15954
链接:http://www.osvdb.org/15954
来源:OSVDB
名称:15953
链接:http://www.osvdb.org/15953
来源:OSVDB
名称:15952
链接:http://www.osvdb.org/15952
来源:OSVDB
名称:15951
链接:http://www.osvdb.org/15951
来源:SECTRACK
名称:1013853
链接:http://securitytracker.com/id?1013853
来源:SECUNIA
名称:15181
链接:http://secunia.com/advisories/15181
来源:MISC
链接:http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html

相关推荐: SSH Communications SSH Tectia Server Private Key Disclosure Vulnerability

SSH Communications SSH Tectia Server Private Key Disclosure Vulnerability 漏洞ID 1098734 漏洞类型 Design Error 发布时间 2004-03-23 更新时间 2004…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享