漏洞信息详情
e107网站系统多个脚本HTML注入漏洞
- CNNVD编号:CNNVD-200412-430
- 危害等级: 中危
- CVE编号:
CVE-2004-2261
- 漏洞类型:
跨站脚本
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
e107 - 漏洞来源:
Discovery is credi… -
漏洞简介
e107中存在跨站脚本(XSS)漏洞。远程攻击者可以借助(1)新闻提交或(2)文章提交函数中的\”login name/author\”字段注入任意脚本或HTML。
漏洞公告
This issue has been reported to be fixed by the vendor:
e107.org e107 website system 0.545
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.554
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.555 Beta
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.6 13
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.6 12
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.6 10
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.6 11
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.6 14
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
e107.org e107 website system 0.603
-
e107.org e107v0.615.tar.gz
http://prdownloads.sourceforge.net/e107/e107v0.615.tar.gz?download
参考网址
来源: BID
名称: 10293
链接:http://www.securityfocus.com/bid/10293
来源: OSVDB
名称: 5982
链接:http://www.osvdb.org/5982
来源: SECUNIA
名称: 11567
链接:http://secunia.com/advisories/11567
来源: XF
名称: e107-news-submit-xss(16087)
链接:http://xforce.iss.net/xforce/xfdb/16087
来源: SECTRACK
名称: 1010084
链接:http://securitytracker.com/id?1010084