多个Vbulletin跨站脚本攻击漏洞

漏洞信息详情

多个Vbulletin跨站脚本攻击漏洞

漏洞简介

Jelsoft vBulletin 2.0.0 到 2.2.8版本global.php存在跨站脚本攻击(XSS)漏洞。远程攻击者借助(1) $scriptpath 或(2) $url变量注入任意web脚本或HTML。

漏洞公告

This vulnerability does not affect VBulletin 2.2.9 which will be released in the near future. Users are advised to download a new ‘global.php’ file from the following location:
VBulletin VBulletin 2.2.5

VBulletin VBulletin 2.2.6

VBulletin VBulletin 2.2.7

VBulletin VBulletin 2.2.8

参考网址

来源: BID
名称: 5997
链接:http://www.securityfocus.com/bid/5997

来源: XF
名称: vBulletin-usercp-xss(10407)
链接:http://www.iss.net/security_center/static/10407.php

来源: BUGTRAQ
名称: 20021018 vBulletin XSS Security Bug
链接:http://archives.neohapsis.com/archives/bugtraq/2002-10/0272.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享