OpenBB Member.PHP跨站脚本攻击漏洞

OpenBB Member.PHP跨站脚本攻击漏洞

漏洞ID 1108779 漏洞类型 跨站脚本
发布时间 2005-05-13 更新时间 2005-10-20
图片[1]-OpenBB Member.PHP跨站脚本攻击漏洞-安全小百科CVE编号 CVE-2005-1613
图片[2]-OpenBB Member.PHP跨站脚本攻击漏洞-安全小百科CNNVD-ID CNNVD-200505-1052
漏洞平台 PHP CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/25657
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-1052
|漏洞详情
OpenBulletinBoard(OpenBB)1.0.8中member.php存在跨站脚本攻击(XSS)漏洞,远程攻击者可通过list操作中的reverse参数来注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/13625/info

OpenBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

This issue reportedly affects OpenBB version 1.0.8; other versions may also be vulnerable. 

http://www.example.com/member.php?action=list&page=2&sortorder=username&perpage=25&reverse="><script>alert('test');</script>
|参考资料

来源:BID
名称:13625
链接:http://www.securityfocus.com/bid/13625
来源:BUGTRAQ
名称:20050513OpenBBSQLInjection&Cross-siteScriptingVulnerability;
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=111601780332632&w;=2

相关推荐: Armidale Software Yapp Conferencing System 2.2 – Local Buffer Overflow

Armidale Software Yapp Conferencing System 2.2 – Local Buffer Overflow 漏洞ID 1053358 漏洞类型 发布时间 1998-01-20 更新时间 1998-01-20 CVE编号 N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享