漏洞信息详情
Fluid Dynamics Search Engine跨站脚本漏洞
- CNNVD编号:CNNVD-200210-158
- 危害等级: 高危
- CVE编号:
CVE-2002-1036
- 漏洞类型:
跨站脚本
- 发布时间:
2002-10-04
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
zoltan_milosevic - 漏洞来源:
Discovered by VALD… -
漏洞简介
Fluid Dynamics Search Engine (FDSE) 2.0.0.0055之前版本的search.pl存在跨站脚本漏洞。远程攻击者借助(1)Rank或者(2)Match参数执行web脚本。
漏洞公告
Zoltan Milosevic has addressed this issue in Fluid Dynamics Search Engine version 2.0.0.0055:
Zoltan Milosevic Fluid Dynamics Search Engine 2.0 .0054
-
Zoltan Milosevic fdse.beta.tar.gzUnix
http://www.xav.com/scripts/search/download/fdse.beta.tar.gz -
Zoltan Milosevic fdse.beta.zipWindows
http://www.xav.com/scripts/search/download/fdse.beta.zip
Zoltan Milosevic Fluid Dynamics Search Engine 2.0 .0052
-
Zoltan Milosevic fdse.beta.tar.gzUnix
http://www.xav.com/scripts/search/download/fdse.beta.tar.gz -
Zoltan Milosevic fdse.beta.zipWindows
http://www.xav.com/scripts/search/download/fdse.beta.zip
Zoltan Milosevic Fluid Dynamics Search Engine 2.0 .0050
-
Zoltan Milosevic fdse.beta.tar.gzUnix
http://www.xav.com/scripts/search/download/fdse.beta.tar.gz -
Zoltan Milosevic fdse.beta.zipWindows
http://www.xav.com/scripts/search/download/fdse.beta.zip
Zoltan Milosevic Fluid Dynamics Search Engine 2.0 .0053
-
Zoltan Milosevic fdse.beta.tar.gzUnix
http://www.xav.com/scripts/search/download/fdse.beta.tar.gz -
Zoltan Milosevic fdse.beta.zipWindows
http://www.xav.com/scripts/search/download/fdse.beta.zip
Zoltan Milosevic Fluid Dynamics Search Engine 2.0 .0051
-
Zoltan Milosevic fdse.beta.tar.gzUnix
http://www.xav.com/scripts/search/download/fdse.beta.tar.gz -
Zoltan Milosevic fdse.beta.zipWindows
http://www.xav.com/scripts/search/download/fdse.beta.zip
参考网址
来源: BID
名称: 5199
链接:http://www.securityfocus.com/bid/5199
来源: XF
名称: fd-search-xss(9533)
链接:http://www.iss.net/security_center/static/9533.php
来源: www.xav.com
链接:http://www.xav.com/scripts/search/changes.htm#4
来源: BUGTRAQ
名称: 20020710 XSS Hole in Fluid Dynamics search Engine
链接:http://archives.neohapsis.com/archives/bugtraq/2002-07/0096.html
来源: BUGTRAQ
名称: 20020710 RE: XSS Hole in Fluid Dynamics Search engine
链接:http://archives.neohapsis.com/archives/bugtraq/2002-07/0094.html