AderSoftware CFBB ‘Index.CFM’ 跨站脚本漏洞

AderSoftware CFBB ‘Index.CFM’ 跨站脚本漏洞

漏洞ID 1108956 漏洞类型 跨站脚本
发布时间 2005-08-01 更新时间 2005-10-20
图片[1]-AderSoftware CFBB ‘Index.CFM’ 跨站脚本漏洞-安全小百科CVE编号 CVE-2005-2560
图片[2]-AderSoftware CFBB ‘Index.CFM’ 跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200508-138
漏洞平台 CFM CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/26060
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200508-138
|漏洞详情
CFBB1.1.0中的index.cfm存在跨站脚本漏洞。这使得远程攻击者可以借助于页码参数注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/14440/info

CFBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

This issue affects CFBB version 1.1.0; other versions may also be vulnerable.

http://www.example.com/forums/index.cfm?page=XSS
|参考资料

来源:BID
名称:14440
链接:http://www.securityfocus.com/bid/14440
来源:SECUNIA
名称:16311
链接:http://secunia.com/advisories/16311
来源:BUGTRAQ
名称:20050805XSSinforumsCFBBv1.1.0
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112352059715868&w;=2

相关推荐: Progress sqlcpp Local Buffer Overflow Vulnerability

Progress sqlcpp Local Buffer Overflow Vulnerability 漏洞ID 1102293 漏洞类型 Boundary Condition Error 发布时间 2002-03-22 更新时间 2002-03-22 CVE…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享