phpPgAdmin ‘redirect.php’&login.php 跨站脚本攻击漏洞

漏洞信息详情

phpPgAdmin ‘redirect.php’&login.php 跨站脚本攻击漏洞

漏洞简介

phpPgAdmin 3.5中存在跨站脚本攻击漏洞。远程攻击者可以借助(1) redirect.php, 和(2) login.php的PHP_SELF中某些可用的输入信息,注入任意web脚本或HTML。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Debian Linux 4.0 amd64

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 ia-32

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 arm

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 hppa

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 sparc

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 s/390

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 powerpc

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 alpha

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 m68k

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 mipsel

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 ia-64

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 4.0 mips

Debian sitebar_3.3.8-7etch1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7

etch1_all.deb

Debian Linux 3.1 ppc

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 ia-64

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 arm

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 mips

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 ia-32

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 alpha

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 m68k

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 mipsel

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 s/390

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 amd64

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 hppa

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

Debian Linux 3.1 sparc

Debian sitebar_3.2.6-7.1sarge1_all.deb

http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7

.1sarge1_all.deb

SiteBar SiteBar 3.2.6

SiteBar SiteBar-3.3.9.tar.bz2

http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime

=1192322139&big_mirror=0

SiteBar SiteBar 3.3.2

SiteBar SiteBar-3.3.9.tar.bz2

http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime

=1192322139&big_mirror=0

SiteBar SiteBar 3.3.3

SiteBar SiteBar-3.3.9.tar.bz2

http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime

=1192322139&b

参考网址

来源: XF

名称: phppgadmin-redirect-xss(34550)

链接:http://xforce.iss.net/xforce/xfdb/34550

来源: BID

名称: 24182

链接:http://www.securityfocus.com/bid/24182

来源: DEBIAN

名称: DSA-1693

链接:http://www.debian.org/security/2008/dsa-1693

来源: SECUNIA

名称: 33263

链接:http://secunia.com/advisories/33263

来源: SECUNIA

名称: 25446

链接:http://secunia.com/advisories/25446

来源: FULLDISC

名称: 20070527 phpPgAdmin Multiple XSS Vulnerabilities

链接:http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063617.html

来源: SUSE

名称: SUSE-SR:2007:024

链接:http://www.novell.com/linux/security/advisories/2007_24_sr.html

来源: SECUNIA

名称: 27756

链接:http://secunia.com/advisories/27756

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享