Simple Machines X-Forwarded-For ‘Sources/Register.php’跨站脚本攻击漏洞

漏洞信息详情

Simple Machines X-Forwarded-For ‘Sources/Register.php’跨站脚本攻击漏洞

漏洞简介

Simple Machine Forum (SMF) 1.0.6的Sources/Register.php中存在跨站脚本攻击(XSS)漏洞。远程攻击者可以借助X-Forwarded-For HTTP报头字段注入任意Web脚本或HTML。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,厂商发布了相关更新。

Simple Machines SMF 1.0 -beta4.1

Simple Machines SMF 1.0.7

http://www.simplemachines.org/download/

Simple Machines SMF 1.0 -beta4p

Simple Machines SMF 1.0.7

http://www.simplemachines.org/download/

Simple Machines SMF 1.0 -beta5p

Simple Machines SMF 1.0.7

http://www.simplemachines.org/download/

Simple Machines SMF 1.0.2

Simple Machines SMF 1.0.7

http://www.simplemachines.org/download

Simple Machines SMF 1.0.4

Simple Machines SMF 1.0.7

http://www.simplemachines.org/download

Simple Machines SMF 1.0.5

Simple Machines SMF 1.0.7

http://www.simplemachines.org/download/

Simple Machines SMF 1.0.6

Simple Machines SMF 1.0.7

http://www.simplemachines.org/download

参考网址

来源: VUPEN

名称: ADV-2006-0726

链接:http://www.frsirt.com/english/advisories/2006/0726

来源: SECUNIA

名称: 19004

链接:http://secunia.com/advisories/19004

来源: MISC

链接:http://evuln.com/vulns/86/summary.html

来源: XF

名称: smf-register-xss(24915)

链接:http://xforce.iss.net/xforce/xfdb/24915

来源: www.simplemachines.org

链接:http://www.simplemachines.org/community/index.php?topic=78841.0

来源: BID

名称: 16841

链接:http://www.securityfocus.com/bid/16841

来源: BUGTRAQ

名称: 20060306 [eVuln] Simple Machines Forum – SMF ‘X-Forwarded-For’ XSS Vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/426824/100/0/threaded

来源: OSVDB

名称: 23480

链接:http://www.osvdb.org/23480

来源: SREASON

名称: 545

链接:http://securityreason.com/securityalert/545

来源: VIM

名称: 20060410 VEndor ACK: Simple Machines Forum Register.php X-Forwarded-For XSS

链接:http://attrition.org/pipermail/vim/2006-April/000682.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享