e107网站系统多个脚本HTML注入漏洞

漏洞信息详情

e107网站系统多个脚本HTML注入漏洞

漏洞简介

e107中存在跨站脚本(XSS)漏洞。远程攻击者可以借助(1)新闻提交或(2)文章提交函数中的\”login name/author\”字段注入任意脚本或HTML。

漏洞公告

This issue has been reported to be fixed by the vendor:
e107.org e107 website system 0.545

e107.org e107 website system 0.554

e107.org e107 website system 0.555 Beta

e107.org e107 website system 0.6 13

e107.org e107 website system 0.6 12

e107.org e107 website system 0.6 10

e107.org e107 website system 0.6 11

e107.org e107 website system 0.6 14

e107.org e107 website system 0.603

参考网址

来源: BID
名称: 10293
链接:http://www.securityfocus.com/bid/10293

来源: OSVDB
名称: 5982
链接:http://www.osvdb.org/5982

来源: SECUNIA
名称: 11567
链接:http://secunia.com/advisories/11567

来源: XF
名称: e107-news-submit-xss(16087)
链接:http://xforce.iss.net/xforce/xfdb/16087

来源: SECTRACK
名称: 1010084
链接:http://securitytracker.com/id?1010084

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享