Ecometry SGDynamo跨站脚本攻击(XSS)漏洞

漏洞信息详情

Ecometry SGDynamo跨站脚本攻击(XSS)漏洞

漏洞简介

Sgdynamo的sgdynamo.exe存在跨站脚本攻击(XSS)漏洞。远程攻击者可以借助HTNAME参数中带有脚本的URL执行任意Javascript。

漏洞公告

The vendor has released fixes for versions 5.32T are later. Those affected are advised to contact their Ecometry Customer Support Rep in order to obtain the fixed code. Users should reference Job # 181625-01 when requesting information about the availablity of fixes.

参考网址

来源: XF
名称: sgdynamo-htname-parameter-xss(9830)
链接:http://xforce.iss.net/xforce/xfdb/9830

来源: OSVDB
名称: 3458
链接:http://www.osvdb.org/3458

来源: VULN-DEV
名称: 20020417 Smalls holes on 5 products #1
链接:http://marc.theaimsgroup.com/?l=vuln-dev&m=101908986415768&w=2

来源: BUGTRAQ
名称: 20020510 Fix available for Sgdynamo
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=102107488402057&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享