PHPGroupWare Wiki跨站脚本漏洞

漏洞信息详情

PHPGroupWare Wiki跨站脚本漏洞

漏洞简介

Phpgroupware (又称为webdistro)0.9.16.002及其以前的版本存在多个跨站脚本(XSS)漏洞。远程攻击者利用该漏洞插入任意HTML或网页脚本,正如wiki模块的请求。

漏洞公告

Gentoo has released updates that may be applied with the following commands:
emerge sync
emerge -pv “>=www-apps/phpgroupware-0.9.16.003”
emerge “>=www-apps/phpgroupware-0.9.16.003”
The vendor has released version 0.9.16.003 addressing this issue:
PHPGroupWare PHPGroupWare 0.9.12

PHPGroupWare PHPGroupWare 0.9.13

PHPGroupWare PHPGroupWare 0.9.14 .006

PHPGroupWare PHPGroupWare 0.9.14 .005

PHPGroupWare PHPGroupWare 0.9.14 .003

PHPGroupWare PHPGroupWare 0.9.14 .007

PHPGroupWare PHPGroupWare 0.9.16 RC1

PHPGroupWare PHPGroupWare 0.9.16 .000

PHPGroupWare PHPGroupWare 0.9.16 .002

参考网址

来源: XF
名称: phpgroupware-xss(17289)
链接:http://xforce.iss.net/xforce/xfdb/17289

来源: GENTOO
名称: GLSA-200409-22
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-22.xml

来源: downloads.phpgroupware.org
链接:http://downloads.phpgroupware.org/changelog

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享