漏洞信息详情
JSPWiki跨站脚本漏洞
- CNNVD编号:CNNVD-200412-183
- 危害等级: 中危
![图片[1]-JSPWiki跨站脚本漏洞-一一网](https://www.proyy.com/skycj/data/images/2021-09-07/30f462579bec41fc25e0b1d57503e6d6.png)
- CVE编号:
CVE-2004-1544
- 漏洞类型:
跨站脚本
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
jspwiki - 漏洞来源:
Jeremy Bae at STG … -
漏洞简介
JSPWiki 2.1.120-cvs及之前版本中的Search.jsp存在跨站脚本(XSS)漏洞。远程攻击者可以像其他用户借助query参数来执行任意web脚本。
漏洞公告
The vendor has released version 2.1.123 to address this issue. Please note that this release is directly from the CVS repository from the project, and may not be stable.
JSPWiki JSPWiki 2.1.120
-
JSPWiki JSPWiki-latest.zip
http://www.ecyrd.com/~jalkanen/JSPWiki/nightly/JSPWiki-latest.zip
JSPWiki JSPWiki 2.1.121
-
JSPWiki JSPWiki-latest.zip
http://www.ecyrd.com/~jalkanen/JSPWiki/nightly/JSPWiki-latest.zip
JSPWiki JSPWiki 2.1.122
-
JSPWiki JSPWiki-latest.zip
http://www.ecyrd.com/~jalkanen/JSPWiki/nightly/JSPWiki-latest.zip
参考网址
来源: XF
名称: jspwiki-query-xss(18236)
链接:http://xforce.iss.net/xforce/xfdb/18236
来源: BID
名称: 11746
链接:http://www.securityfocus.com/bid/11746
来源: SECUNIA
名称: 13285
链接:http://secunia.com/advisories/13285/
来源: BUGTRAQ
名称: 20041124 STG Security Advisory: [SSA-20041122-11] JSPWiki XSS vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110135663220831&w=2
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END




















![[桜井宁宁]COS和泉纱雾超可爱写真福利集-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/4d3cf227a85d7e79f5d6b4efb6bde3e8.jpg)

![[桜井宁宁] 爆乳奶牛少女cos写真-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/d40483e126fcf567894e89c65eaca655.jpg)