漏洞信息详情
Phorum Multiple Module跨站脚本漏洞
- CNNVD编号:CNNVD-200403-055
- 危害等级: 中危
- CVE编号:
CVE-2004-1822
- 漏洞类型:
跨站脚本
- 发布时间:
2004-03-15
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
phorum - 漏洞来源:
Discovery is credi… -
漏洞简介
Phorum 3.1到5.0.3测试版存在多个跨站脚本漏洞。远程攻击者借助(1)login.php的HTTP_REFERER参数,(2)register.php的HTTP_REFERER参数,或(3)profile.php的target参数注入任意web脚本或HTML。
漏洞公告
Fixes are available.
Phorum Phorum 3.1
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.1.1 rc2
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.1.1 a
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.1.1 pre
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.1.1
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.1.2
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.2
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.3
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.3 b
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.3 a
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.4
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.5
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.6
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.7
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.2.8
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.3.1
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.3.1 a
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.3.2 a
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.3.2 b3
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.3.2
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.4
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.4.1
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.4.2
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.4.3
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.4.4
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.4.5
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
Phorum Phorum 3.4.6
-
Phorum phorum-3.4.7.tar.gz
http://www.phorum.org/downloads/phorum-3.4.7.tar.gz
参考网址
来源: BID
名称: 9882
链接:http://www.securityfocus.com/bid/9882
来源: SECUNIA
名称: 11157
链接:http://secunia.com/advisories/11157
来源: XF
名称: phorum-register-xss(15494)
链接:http://xforce.iss.net/xforce/xfdb/15494
来源: phorum.org
链接:http://phorum.org/changelog.txt
来源: BUGTRAQ
名称: 20040315 Phorum 5.0.3 Beta && Earlier XSS Issues
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107939479713136&w=2
来源: OSVDB
名称: 4335
链接:http://www.osvdb.org/4335
来源: OSVDB
名称: 4334
链接:http://www.osvdb.org/4334
来源: OSVDB
名称: 4333
链接:http://www.osvdb.org/4333
来源: SECTRACK
名称: 1009433
链接:http://securitytracker.com/id?1009433