Fusebox 跨站脚本攻击漏洞

Fusebox 跨站脚本攻击漏洞

漏洞ID 1108963 漏洞类型 跨站脚本
发布时间 2005-08-03 更新时间 2005-10-20
图片[1]-Fusebox 跨站脚本攻击漏洞-安全小百科CVE编号 CVE-2005-2480
图片[2]-Fusebox 跨站脚本攻击漏洞-安全小百科CNNVD-ID CNNVD-200508-069
漏洞平台 CFM CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/26065
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200508-069
|漏洞详情
Fusebox是用于创建ColdFusion和PHPWeb应用程序的流行框架。Fusebox中存在跨站脚本攻击漏洞,成功利用这个漏洞的攻击者可以以受害用户的权限执行任意代码。起因是没有正确的过滤用户输入,攻击者可以利用这个漏洞将用户重新定向至受控站点上的php脚本,并将用户cookie用作脚本的参数。
|漏洞EXP
source: http://www.securityfocus.com/bid/14460/info

Fusebox is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

This issue reportedly affects Fusebox version 4.1.0; other versions may also be vulnerable.

This issue is not believed to exist because the product does not ship with layout configuration files; this has not been confirmed by Symantec. 

http://www.example.com/index.cfm?fuseaction="><script>alert(document.cookie)</script><
http://www.example.com/index.cfm?fuseaction=fusebox.overview"><script>alert(document.cookie)</script><
|参考资料

来源:BID
名称:14460
链接:http://www.securityfocus.com/bid/14460
来源:SECUNIA
名称:16320
链接:http://secunia.com/advisories/16320
来源:XF
名称:fusebox-fuseaction-xss(21697)
链接:http://xforce.iss.net/xforce/xfdb/21697
来源:BUGTRAQ
名称:20050803ColdfusionFuseboxV4.1.0Vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112309656102615&w;=2

相关推荐: Microsoft IE4剪贴板粘贴漏洞

Microsoft IE4剪贴板粘贴漏洞 漏洞ID 1105409 漏洞类型 访问验证错误 发布时间 1999-01-21 更新时间 2005-10-20 CVE编号 CVE-1999-1453 CNNVD-ID CNNVD-199902-010 漏洞平台 W…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享