CodeThat.com CodeThatShoppingCart多个输入验证漏洞

CodeThat.com CodeThatShoppingCart多个输入验证漏洞

漏洞ID 1108764 漏洞类型 跨站脚本
发布时间 2005-05-09 更新时间 2005-10-20
图片[1]-CodeThat.com CodeThatShoppingCart多个输入验证漏洞-安全小百科CVE编号 CVE-2005-1593
图片[2]-CodeThat.com CodeThatShoppingCart多个输入验证漏洞-安全小百科CNNVD-ID CNNVD-200505-1044
漏洞平台 PHP CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/25637
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-1044
|漏洞详情
CodeThatShoppingCart1.3.1中的catalog.php存在跨站脚本攻击(XSS)漏洞,远程攻击者可通过id参数注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/13560/info

CodeThatShoppingCart is reportedly affected by multiple input validation vulnerabilities. These issues may allow remote attackers to carry out cross-site scripting and SQL injection attacks. An attacker may also potentially disclose sensitive data.

CodeThatShoppingCart 1.3.1 was reported to be vulnerable. Other versions may be affected as well. 

http://www.example.com/codethat/catalog.php?action=category_show
&id=2"><script>alert(document.cookie)</script>
|参考资料

来源:BID
名称:13560
链接:http://www.securityfocus.com/bid/13560
来源:OSVDB
名称:16155
链接:http://www.osvdb.org/16155
来源:SECTRACK
名称:1013924
链接:http://securitytracker.com/id?1013924
来源:SECUNIA
名称:15251
链接:http://secunia.com/advisories/15251
来源:MISC
链接:http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html

相关推荐: Pi3Web Malformed GET Request Denial Of Service Vulnerability

Pi3Web Malformed GET Request Denial Of Service Vulnerability 漏洞ID 1100404 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 2003-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享