Splatt Forum图像标签HTML注入漏洞

漏洞信息详情

Splatt Forum图像标签HTML注入漏洞

漏洞简介

Splatt Forum 3.0版本存在跨站脚本漏洞。远程攻击者可以像其他用户一样借助跟随脚本的带结尾引用的[img]标签执行任意脚本。

漏洞公告

Reportedly this issue has been addressed in Splatt Forum 3.1. Currently only version 3.0 is available for download, administrators should frequently check the vendor site for the latest version.

参考网址

来源: XF
名称: splatt-forum-img-xss(9279)
链接:http://www.iss.net/security_center/static/9279.php

来源: BID
名称: 4953
链接:http://www.securityfocus.com/bid/4953

来源: BUGTRAQ
名称: 20020606 Splatt Forum XSS
链接:http://online.securityfocus.com/archive/1/275744

来源: VULNWATCH
名称: 20020606 [VulnWatch] Splatt Forum XSS
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0091.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享