Net Portal Dynamic System (NPDS) 5.0多个跨站脚本攻击(XSS)漏洞

Net Portal Dynamic System (NPDS) 5.0多个跨站脚本攻击(XSS)漏洞

漏洞ID 1108818 漏洞类型 跨站脚本
发布时间 2005-05-28 更新时间 2005-10-20
图片[1]-Net Portal Dynamic System (NPDS) 5.0多个跨站脚本攻击(XSS)漏洞-安全小百科CVE编号 CVE-2005-1803
图片[2]-Net Portal Dynamic System (NPDS) 5.0多个跨站脚本攻击(XSS)漏洞-安全小百科CNNVD-ID CNNVD-200505-1229
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/25750
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-1229
|漏洞详情
NetPortalDynamicSystem(NPDS)5.0存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可以通过传给(1)admin.php或(2)powerpack_f.php的语言参数,(3)传给sdv_infos.php的sitename参数,(4)传给faq.php的categories参数,(5)传给glossaire模块的lettre参数,(6)传给reviews.php的title参数,或者(7)传给reply.php的image_subject参数,来注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/13803/info
        
NPDS is affected by multiple vulnerabilities resulting from input validation errors. These issues may allow remote attackers to carry out HTML injection, cross-site scripting and SQL injection attacks.
        
This may result in the theft of authentication credentials, destruction or disclosure of sensitive data, and potentially other attacks.
        
All versions of NPDS are considered vulnerable to this issue at the moment.

http://www.example.com/faq.php?myfaq=ys&id_cat=99&categories=<script>alert()</script>
|参考资料

来源:SECTRACK
名称:1014073
链接:http://securitytracker.com/id?1014073
来源:www.npds.org
链接:http://www.npds.org/download.php?op=geninfo&did;=115
来源:OSVDB
名称:16922
链接:http://www.osvdb.org/16922
来源:OSVDB
名称:16464
链接:http://www.osvdb.org/16464

相关推荐: Firefly Studios Stronghold 2 Remote Denial of Service Vulnerability

Firefly Studios Stronghold 2 Remote Denial of Service Vulnerability 漏洞ID 1096565 漏洞类型 Failure to Handle Exceptional Conditions 发布时…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享