osCommerce osCsid参数跨站脚本漏洞

漏洞信息详情

osCommerce osCsid参数跨站脚本漏洞

漏洞简介

osCommerce 2.2-MS3之前版本中html_output.php的tep_href_link函数存在跨站脚本(XSS)漏洞。远程攻击者可以借助osCsid参数注入任意web脚本或HTML。

漏洞公告

It has been reported that osCommerce 2.2 Milestone 3 is not affected by this issue. Users are advised to contact the vendor for more information about obtaining fixes.

参考网址

来源: BID
名称: 9238
链接:http://www.securityfocus.com/bid/9238

来源: BUGTRAQ
名称: 20031217 osCommerce Malformed Session ID XSS Vuln
链接:http://www.securityfocus.com/archive/1/347831

来源: www.oscommerce.com
链接:http://www.oscommerce.com/community/bugs,1546

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享