ReciPants SQL注入和跨站脚本漏洞

漏洞信息详情

ReciPants SQL注入和跨站脚本漏洞

漏洞简介

ReciPants 1.1.1版本存在多个跨站脚本(XSS)漏洞。远程攻击者借助(1)user id,(2) recipe id,(3) category id,和(4)其他的ID号码字段注入任意web脚本或者HTML。

漏洞公告

The vendor has released an upgrade dealing with this issue.
ReciPants ReciPants 1.0

ReciPants ReciPants 1.0.1

ReciPants ReciPants 1.1

ReciPants ReciPants 1.1.1

参考网址

来源: BID
名称: 10250
链接:http://www.securityfocus.com/bid/10250

来源: OSVDB
名称: 5787
链接:http://www.osvdb.org/5787

来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?group_id=90737&release_id=234415

来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?group_id=90737&release_id=234415

来源: SECTRACK
名称: 1009984
链接:http://securitytracker.com/id?1009984

来源: SECUNIA
名称: 11533
链接:http://secunia.com/advisories/11533

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享