SCT Campus Pipeline电子邮件附件脚本注入漏洞

漏洞信息详情

SCT Campus Pipeline电子邮件附件脚本注入漏洞

漏洞简介

SCT Campus Pipeline存在跨站脚本(XSS)漏洞。远程攻击者可以通过电子邮件附件中的onload, onmouseover以及其他Javascript事件注入任意的web脚本或者HTML。

漏洞公告

The vendor has acknowledged this issue and provided resolution information via customer support services. This issue has been assigned answer ID 923 by the vendor. Users should contact the vendor for more information.

参考网址

来源: BID
名称: 10154
链接:http://www.securityfocus.com/bid/10154

来源: SECUNIA
名称: 11396
链接:http://secunia.com/advisories/11396

来源: XF
名称: sct-campus-attachment-xss(15878)
链接:http://xforce.iss.net/xforce/xfdb/15878

来源: BUGTRAQ
名称: 20040415 SCT javascript execution vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108207280917231&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享