PunBB misc.php 跨站脚本攻击(XSS) 漏洞

漏洞信息详情

PunBB misc.php 跨站脚本攻击(XSS) 漏洞

漏洞简介

PunBB 1.2.11的misc.php 存在跨站脚本攻击(XSS) 漏洞。远程攻击者可以借助req_message参数注入任意Web脚本或HTML,因为redirect_url 参数未清理。

漏洞公告

目前厂商还没有提供补丁或者升级程序,建议使用此软件的用户随时关注厂商的主页以获取最新版本:

PunBB PunBB 1.0 RC1

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.0

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.0 _beta2

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.0 RC2

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.0 _beta3

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.0 _alpha

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.0 _beta1

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.0.1

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.1.1

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.1.2

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.1.3

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.1.4

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.1.5

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.1

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.10

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.10

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.11

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.2

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.3

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.4

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.5

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.6

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.7

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.8

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz

PunBB PunBB 1.2.9

PunBB punbb-1.2.12.tar.gz

http://www.punbb.org/download/punbb-1.2.12.tar.gz\

参考网址

来源: BUGTRAQ

名称: 20060503 PunBB1.2.11 Cross-Site Scripting

链接:http://www.securityfocus.com/archive/1/archive/1/432950/100/0/threaded

来源: SECUNIA

名称: 19986

链接:http://secunia.com/advisories/19986

来源: XF

名称: punbb-misc-xss(26245)

链接:http://xforce.iss.net/xforce/xfdb/26245

来源: BID

名称: 17827

链接:http://www.securityfocus.com/bid/17827

来源: www.punbb.org

链接:http://www.punbb.org/download/hdiff/hdiff-1.2.11_to_1.2.12.html

来源: www.punbb.org

链接:http://www.punbb.org/changelogs/1.2.11_to_1.2.12.txt

来源: OSVDB

名称: 25256

链接:http://www.osvdb.org/25256

来源: VUPEN

名称: ADV-2006-1670

链接:http://www.frsirt.com/english/advisories/2006/1670

来源: SREASON

名称: 849

链接:http://securityreason.com/securityalert/849

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享