Icecast服务器状态显示跨站脚本漏洞

漏洞信息详情

Icecast服务器状态显示跨站脚本漏洞

漏洞简介

Icecast内部网络服务器(icecast-server) 1.3.12版本及之前的版本中的list.cgi存在跨站脚本(XSS)漏洞。远程攻击者借助UserAgent参数注入任意web脚本。

漏洞公告

Debian has released advisory DSA 541-1 dealing with this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
Icecast Icecast 1.3.11
@securityfocus.com>

参考网址

来源: XF
名称: icecast-list-useragent-xss(17086)
链接:http://xforce.iss.net/xforce/xfdb/17086

来源: BID
名称: 11021
链接:http://www.securityfocus.com/bid/11021

来源: DEBIAN
名称: DSA-541
链接:http://www.debian.org/security/2004/dsa-541

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享