MyGuestbook脚本注入漏洞

漏洞信息详情

MyGuestbook脚本注入漏洞

漏洞简介

MyGuestbook 1.0版本存在跨站脚本漏洞。远程攻击者可以借助 (1)用户名或(2)注释字段执行任意脚本或注入HTML。

漏洞公告

Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: BID
名称: 4651
链接:http://www.securityfocus.com/bid/4651

来源: XF
名称: myguestbook-cgi-css(8968)
链接:http://www.iss.net/security_center/static/8968.php

来源: BUGTRAQ
名称: 20020430 Levcgi.coms MyGuestbook JavaScript Injection Vulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2002-04/0422.html

来源: www.levcgi.com
链接:http://www.levcgi.com/programs.cgi?program=myguestbook&action=history

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享