漏洞信息详情
Ecometry SGDynamo跨站脚本攻击(XSS)漏洞
- CNNVD编号:CNNVD-200205-095
- 危害等级: 中危
- CVE编号:
CVE-2002-0375
- 漏洞类型:
跨站脚本
- 发布时间:
2002-05-29
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
ecometry - 漏洞来源:
Discovery of this … -
漏洞简介
Sgdynamo的sgdynamo.exe存在跨站脚本攻击(XSS)漏洞。远程攻击者可以借助HTNAME参数中带有脚本的URL执行任意Javascript。
漏洞公告
The vendor has released fixes for versions 5.32T are later. Those affected are advised to contact their Ecometry Customer Support Rep in order to obtain the fixed code. Users should reference Job # 181625-01 when requesting information about the availablity of fixes.
参考网址
来源: XF
名称: sgdynamo-htname-parameter-xss(9830)
链接:http://xforce.iss.net/xforce/xfdb/9830
来源: OSVDB
名称: 3458
链接:http://www.osvdb.org/3458
来源: VULN-DEV
名称: 20020417 Smalls holes on 5 products #1
链接:http://marc.theaimsgroup.com/?l=vuln-dev&m=101908986415768&w=2
来源: BUGTRAQ
名称: 20020510 Fix available for Sgdynamo
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=102107488402057&w=2