NetworkActiv Web Server 跨站脚本漏洞

NetworkActiv Web Server 跨站脚本漏洞

漏洞ID 1108968 漏洞类型 跨站脚本
发布时间 2005-08-04 更新时间 2005-10-20
图片[1]-NetworkActiv Web Server 跨站脚本漏洞-安全小百科CVE编号 CVE-2005-2453
图片[2]-NetworkActiv Web Server 跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200508-052
漏洞平台 Multiple CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/26071
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200508-052
|漏洞详情
NetworkActivWebServer1.0,2.0.0.6,3.0.1.1,3.5.13及其它可能版本中存在跨站脚本(XSS)漏洞。这使得远程攻击者可以借助于查询字符串注入任意的Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/14473/info

NetworkActiv Web Server is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. 

http://www.example.com?">[code]
|参考资料

来源:MISC
链接:http://secunia.com/secunia_research/2005-31/advisory/
来源:SECUNIA
名称:16301
链接:http://secunia.com/advisories/16301
来源:XF
名称:networkactiv-xss(21696)
链接:http://xforce.iss.net/xforce/xfdb/21696
来源:BID
名称:14473
链接:http://www.securityfocus.com/bid/14473
来源:OSVDB
名称:18525
链接:http://www.osvdb.org/18525
来源:SECTRACK
名称:1014624
链接:http://securitytracker.com/id?1014624

相关推荐: Internet Explorer漏洞

Internet Explorer漏洞 漏洞ID 1205650 漏洞类型 未知 发布时间 2001-06-27 更新时间 2001-06-27 CVE编号 CVE-2001-0332 CNNVD-ID CNNVD-200106-172 漏洞平台 N/A CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享