Joel Palmius Mod_Survey调查输入字段HTML注入漏洞

漏洞信息详情

Joel Palmius Mod_Survey调查输入字段HTML注入漏洞

漏洞简介

Mod_survey 3.0.16-pre2之前3.0.x版本和3.2.0-pre4之前3.2.x版本存在漏洞。远程攻击者可以借助某些调查字段或畸形查询字符串中的错误消息,注入任意web脚本或HTML。

漏洞公告

This issue has been addressed in Mod_Survey versions 3.0.16-pre2 (stable branch) and 3.2.0-pre4 (development branch).
Joel Palmius Mod_Survey 3.0 .0

Joel Palmius Mod_Survey 3.0 .4

Joel Palmius Mod_Survey 3.0 .6

Joel Palmius Mod_Survey 3.0 .2

Joel Palmius Mod_Survey 3.0 .5

Joel Palmius Mod_Survey 3.0 .10

Joel Palmius Mod_Survey 3.0 .1

Joel Palmius Mod_Survey 3.0 .3

Joel Palmius Mod_Survey 3.0.11

Joel Palmius Mod_Survey 3.0.12

Joel Palmius Mod_Survey 3.0.13

Joel Palmius Mod_Survey 3.0.14 d

Joel Palmius Mod_Survey 3.0.14 e

Joel Palmius Mod_Survey 3.0.14

Joel Palmius Mod_Survey 3.0.15 -pre5

Joel Palmius Mod_Survey 3.0.15 -pre6

Joel Palmius Mod_Survey 3.0.15 -pre3

Joel Palmius Mod_Survey 3.0.15 -pre1

Joel Palmius Mod_Survey 3.0.15 -pre2

Joel Palmius Mod_Survey 3.0.15

Joel Palmius Mod_Survey 3.0.15 -pre4

Joel Palmius Mod_Survey 3.0.16 -pre1

Joel Palmius Mod_Survey 3.0.9

Joel Palmius Mod_Survey 3.2 .0-pre3

Joel Palmius Mod_Survey 3.2 .0-pre2

Joel Palmius Mod_Survey 3.2 .0-pre1

参考网址

来源: BID
名称: 9941
链接:http://www.securityfocus.com/bid/9941

来源: SECTRACK
名称: 1009516
链接:http://securitytracker.com/id?1009516

来源: XF
名称: modsurvey-xss(15582)
链接:http://xforce.iss.net/xforce/xfdb/15582

来源: BUGTRAQ
名称: 20040322 Mod_Survey security advisory: Script injection bug
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107997967421972&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享