漏洞信息详情
mnoGoSearch多个跨站脚本漏洞
- CNNVD编号:CNNVD-200412-061
- 危害等级: 中危
- CVE编号:
CVE-2004-1059
- 漏洞类型:
跨站脚本
- 发布时间:
2004-12-10
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
mnogosearch - 漏洞来源:
Discovery is credi… -
漏洞简介
mnoGoSearch 3.2.26及其早期版本存在多个跨站脚本(XSS)漏洞。远程攻击者借助搜索网页的(1)下一个和(2)上一个结果,和(3) 延长的和(4)简单的搜索方式,注入任意的HTML和web脚本。
漏洞公告
The vendor has released mnoGoSearch version 3.2.27 to address these issues.
mnoGoSearch mnoGoSearch 3.1.19
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.1.20
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.10
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.13
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.14
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.15
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.16
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.17
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.18
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.19
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.20
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.21
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.22
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.23
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.24
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.25
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
mnoGoSearch mnoGoSearch 3.2.26
-
mnoGoSearch mnogosearch-3.2.27.tar.gz
http://www.mnogosearch.org/Download/mnogosearch-3.2.27.tar.gz
参考网址
来源: XF
名称: mnogosearch-search-xss(18434)
链接:http://xforce.iss.net/xforce/xfdb/18434
来源: BID
名称: 11895
链接:http://www.securityfocus.com/bid/11895
来源: www.mnogosearch.org
链接:http://www.mnogosearch.org/history.html
来源: www.mikx.de
链接:http://www.mikx.de/index.php?p=6
来源: FULLDISC
名称: 20041223 Cross-Site Scripting – an industry-wide problem
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html