VBZooM Forum 多个跨站脚本注入漏洞

VBZooM Forum 多个跨站脚本注入漏洞

漏洞ID 1108950 漏洞类型 跨站脚本
发布时间 2005-07-29 更新时间 2005-10-20
图片[1]-VBZooM Forum 多个跨站脚本注入漏洞-安全小百科CVE编号 CVE-2005-2441
图片[2]-VBZooM Forum 多个跨站脚本注入漏洞-安全小百科CNNVD-ID CNNVD-200508-037
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/26050
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200508-037
|漏洞详情
VBzoom存在多个跨站脚本攻击(XSS)漏洞。这使得远程攻击者可以借助于(1)传递给profile.php的UserName参数或(2)传递给login.php的UserID参数注入任意的Web脚本和HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/14423/info
 
VBZooM Forum is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
 
An attacker may leverage any of these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. 

http://www.example.com/vbzoom/login.php?UserID='<br><script>alert(document.cookie);</script>
|参考资料

来源:XF
名称:vbzoom-profile-login-xss(21680)
链接:http://xforce.iss.net/xforce/xfdb/21680
来源:BID
名称:14423
链接:http://www.securityfocus.com/bid/14423
来源:BUGTRAQ
名称:20060306SQLinjection&XSSINvbzoomv1.11;
链接:http://www.securityfocus.com/archive/1/archive/1/426874/100/0/threaded
来源:OSVDB
名称:18663
链接:http://www.osvdb.org/18663
来源:OSVDB
名称:18662
链接:http://www.osvdb.org/18662
来源:SECTRACK
名称:1014614
链接:http://securitytracker.com/id?1014614
来源:SECUNIA
名称:16220
链接:http://secunia.com/advisories/16220
来源:BUGTRAQ
名称:20050729VBZoomCrossSiteScriptingVulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112300586019568&w;=2

相关推荐: MIT Kerberos 5 (krb5)缓冲区溢出漏洞

MIT Kerberos 5 (krb5)缓冲区溢出漏洞 漏洞ID 1205775 漏洞类型 缓冲区溢出 发布时间 2001-05-16 更新时间 2001-05-16 CVE编号 CVE-2001-1323 CNNVD-ID CNNVD-200105-087…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享