漏洞信息详情
ht://Check Web头脚本注入漏洞
- CNNVD编号:CNNVD-200210-305
- 危害等级: 中危
- CVE编号:
CVE-2002-1195
- 漏洞类型:
跨站脚本
- 发布时间:
2002-10-28
- 威胁类型:
远程
- 更新时间:
2005-05-13
- 厂 商:
gabriele_bartolini - 漏洞来源:
Discovery credited… -
漏洞简介
ht://Check 1.1的PHP接口存在跨站脚本漏洞。远程web服务器可以借助web页面注入任意包含脚本的HTML。
漏洞公告
The following fixes are available:
Gabriele Bartolini ht://Check 1.1
-
Debian htcheck-php_1.1-1.1_all.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck-php_1.1
-1.1_all.deb -
Debian htcheck_1.1-1.1_alpha.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_alpha.deb -
Debian htcheck_1.1-1.1_arm.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_arm.deb -
Debian htcheck_1.1-1.1_hppa.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_hppa.deb -
Debian htcheck_1.1-1.1_i386.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_i386.deb -
Debian htcheck_1.1-1.1_ia64.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_ia64.deb -
Debian htcheck_1.1-1.1_m68k.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_m68k.deb -
Debian htcheck_1.1-1.1_mips.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_mips.deb -
Debian htcheck_1.1-1.1_mipsel.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_mipsel.deb -
Debian htcheck_1.1-1.1_powerpc.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_powerpc.deb -
Debian htcheck_1.1-1.1_s390.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_s390.deb -
Debian htcheck_1.1-1.1_sparc.deb
http://security.debian.org/pool/updates/main/h/htcheck/htcheck_1.1-1.1
_sparc.deb
参考网址
来源: DEBIAN
名称: DSA-169
链接:http://www.debian.org/security/2002/dsa-169
来源: XF
名称: htcheck-server-header-xss(10089)
链接:http://www.iss.net/security_center/static/10089.php
来源: BUGTRAQ
名称: 20020912 ht://Check XSS
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103184269605160&w=2
来源: BID
名称: 5699
链接:http://www.securityfocus.com/bid/5699
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END