UBBCentral UBB.线程多个跨站脚本漏洞

漏洞信息详情

UBBCentral UBB.线程多个跨站脚本漏洞

漏洞简介

Infopop UBB.Threads 6.2.3和6.5版本的(1)calendar.php,(2) login.php,和(3)online.php存在跨站脚本(XSS)漏洞。 远程攻击者可以借助Cat参数注入任意web脚本或HTML。

漏洞公告

Some of these issues may have been fixed in version 6.5 of the affected package.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: OSVDB
名称: 12367
链接:http://www.osvdb.org/12367

来源: OSVDB
名称: 12366
链接:http://www.osvdb.org/12366

来源: OSVDB
名称: 12365
链接:http://www.osvdb.org/12365

来源: XF
名称: ubbthreads-multiple-scripts-xss(18432)
链接:http://xforce.iss.net/xforce/xfdb/18432

来源: BID
名称: 11900
链接:http://www.securityfocus.com/bid/11900

来源: SECTRACK
名称: 1012503
链接:http://securitytracker.com/id?1012503

来源: SECUNIA
名称: 13452
链接:http://secunia.com/advisories/13452

来源: FULLDISC
名称: 20041213 Multiple XSS Vulnerabilities in several UBB.Thread Versions
链接:http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0239.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享