Pubcookies多个跨站脚本攻击漏洞

漏洞信息详情

Pubcookies多个跨站脚本攻击漏洞

漏洞简介

在University of Washington Pubcookie 3.2.1b之前版本 3.0.0, 3.1.0, 3.1.1, 3.2,和3.3.0a之前版本3.3的login服务器中的index.cgi中存在多个跨站脚本攻击XSS)漏洞,远程攻击者可通过不明输入,注入任意Web脚本或HTML。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

University of Washington Pubcookie 3.2.1a

University of Washington pubcookie-3.2.1b.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.2.1b.tar.gz

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

University of Washington Pubcookie 1.0

University of Washington pubcookie-3.2.1b.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.2.1b.tar.gz

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

University of Washington Pubcookie 3.0

University of Washington pubcookie-3.2.1b.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.2.1b.tar.gz

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

University of Washington Pubcookie 3.1

University of Washington pubcookie-3.2.1b.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.2.1b.tar.gz

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

University of Washington Pubcookie 3.1.1

University of Washington pubcookie-3.2.1b.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.2.1b.tar.gz

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

University of Washington Pubcookie 3.2

University of Washington pubcookie-3.2.1b.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.2.1b.tar.gz

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

University of Washington Pubcookie 3.2.1

University of Washington pubcookie-3.2.1b.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.2.1b.tar.gz

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

University of Washington Pubcookie 3.3

University of Washington Pubcookie-3.3.0a.msi

Windows

http://pubcookie.org/downloads/Pubcookie-3.3.0a.msi

University of Washington pubcookie-3.3.0a.tar.gz

Unix

http://pubcookie.org/downloads/pubcookie-3.3.0a.tar.gz

参考网址

来源: US-CERT

名称: VU#337585

链接:http://www.kb.cert.org/vuls/id/337585

来源: XF

名称: pubcookie-login-server-xss(25427)

链接:http://xforce.iss.net/xforce/xfdb/25427

来源: SECUNIA

名称: 19348

链接:http://secunia.com/advisories/19348

来源: pubcookie.org

链接:http://pubcookie.org/news/20060306-login-secadv.html

来源: BID

名称: 17221

链接:http://www.securityfocus.com/bid/17221

来源: OSVDB

名称: 24521

链接:http://www.osvdb.org/24521

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享