Invision Power Board 附件跨站脚本漏洞

Invision Power Board 附件跨站脚本漏洞

漏洞ID 1108992 漏洞类型 输入验证
发布时间 2005-08-08 更新时间 2005-10-20
图片[1]-Invision Power Board 附件跨站脚本漏洞-安全小百科CVE编号 CVE-2005-2542
图片[2]-Invision Power Board 附件跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200508-082
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/26104
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200508-082
|漏洞详情
InvisionPowerBoard(IPB)1.0.3允许远程攻击者借助于自动下载且处理成HTML格式的附件注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/14492/info

Invision Power Board is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

This issue is reported to affect Invision Power Board 1.0.3; other 1.x versions of the application may also be affected. However, the 2.x versions of the application are reported not vulnerable to this issue. 

<html>
<body>
<script>alert('Css found By V[i]RuS');</script>
</body>
</html>
|参考资料

来源:BID
名称:14492
链接:http://www.securityfocus.com/bid/14492
来源:BUGTRAQ
名称:20050805ipbCssbug(nowpublic)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112327712614854&w;=2
来源:SECUNIA
名称:16348
链接:http://secunia.com/advisories/16348

相关推荐: Fastream NetFile FTP/Web Server Directory Traversal Variant Vulnerability

Fastream NetFile FTP/Web Server Directory Traversal Variant Vulnerability 漏洞ID 1096816 漏洞类型 Input Validation Error 发布时间 2005-04-26…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享