MyScrapbook addwords.php 多个跨站脚本攻击(XSS)漏洞

漏洞信息详情

MyScrapbook addwords.php 多个跨站脚本攻击(XSS)漏洞

漏洞简介

MyScrapbook 3.1及之前版本的addwords.php中存在多个跨站脚本攻击(XSS)漏洞。远程攻击者可以借助(1)name和(2)comment参数注入任意Web脚本或HTML。

漏洞公告

目前厂商已经发布了相关补丁,请到厂商的主页下载:

KDE aRts 1.3.2

Slackware arts-1.4.2-i486-2_slack10.2.tgz

Slackware 10.2:

ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ arts-1.4.2-i486-2_slack10.2.tgz

KDE KDE 3.2

KDE post-3.2.0-kdebase-kdm.diff

ftp://ftp.kde.org/pub/kde/security_patches

Mandriva kdebase-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-3.2-79.16.C30mdk.src.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-3.2-79.16.C30mdk.src.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-common-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-common-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-kate-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-kate-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-kcontrol-data-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-kcontrol-data-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-kdeprintfax-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-kdeprintfax-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-kdm-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-kdm-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-kdm-config-file-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-kdm-config-file-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-kmenuedit-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-kmenuedit-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-konsole-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-konsole-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-nsplugins-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-nsplugins-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva kdebase-progs-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva kdebase-progs-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-devel-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-kate-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-kate-devel-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-kmenuedit-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-konsole-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-nsplugins-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva lib64kdebase4-nsplugins-devel-3.2-79.16.C30mdk.x86_64.rpm

Corporate 3.0/X86_64:

http://www.mandriva.com/en/download

Mandriva libkdebase4-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva libkdebase4-devel-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva libkdebase4-kate-3.2-79.16.C30mdk.i586.rpm

Corporate 3.0:

http://www.mandriva.com/en/download

Mandriva libkdebase4-kate-de

参考网址

来源: VUPEN

名称: ADV-2006-2311

链接:http://www.frsirt.com/english/advisories/2006/2311

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享