PHPGroupWare多个跨站脚本和SQL注入漏洞

漏洞信息详情

PHPGroupWare多个跨站脚本和SQL注入漏洞

漏洞简介

phpGroupWare 0.9.16.003及其以前的的版本存在多个跨站脚本(XSS)漏洞。远程攻击者借助(1)kp3,(2)type,(3)msg, (4 forum_id,(5)pos,(6)cats_app,(7)cat_id, (8)msgball[msgnum],(9)index.php的fldball[acctnum]参数或者 (10)viewticket_details.php的ticket_id注入任意web脚本或者HTML。

漏洞公告

Gentoo has released an advisory to provide updates for this issue. Updates may be applied by running the following commands as the superuser:
emerge –sync
emerge –ask –oneshot –verbose “>=www-apps/phpgroupware-0.9.16.004”
The vendor has addressed these issues in PHPGroupWare 0.9.16.005.
PHPGroupWare PHPGroupWare 0.9.12

PHPGroupWare PHPGroupWare 0.9.13

PHPGroupWare PHPGroupWare 0.9.14 .006

PHPGroupWare PHPGroupWare 0.9.14 .005

PHPGroupWare PHPGroupWare 0.9.14 .003

PHPGroupWare PHPGroupWare 0.9.14 .007

PHPGroupWare PHPGroupWare 0.9.16 RC1

PHPGroupWare PHPGroupWare 0.9.16 .000

PHPGroupWare PHPGroupWare 0.9.16 .003

PHPGroupWare PHPGroupWare 0.9.16 .002

参考网址

来源: BID
名称: 11952
链接:http://www.securityfocus.com/bid/11952

来源: GENTOO
名称: GLSA-200501-08
链接:http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml

来源: XF
名称: phpgroupware-index-preferences-xss(18496)
链接:http://xforce.iss.net/xforce/xfdb/18496

来源: www.gulftech.org
链接:http://www.gulftech.org/?node=research&article_id=00054-12142004

来源: BUGTRAQ
名称: 20041215 Multiple phpGroupWare Vulnerabilities [ phpGroupWare 0.9.16.003 && Earlier ]
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110312656029072&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享