phpWebSite多个跨站脚本漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1107448 漏洞类型 跨站脚本
发布时间 2003-08-11 更新时间 2003-10-20
CVE编号 CVE-2003-0736 CNNVD-ID CNNVD-200310-040
漏洞平台 PHP CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/23016
https://www.securityfocus.com/bid/82720
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200310-040
|漏洞详情
phpWebSite0.9.x及其早期版本存在多个跨站脚本(XSS)漏洞。远程攻击者借助(1)calendar模块的day参数,(2)fatcat模块的fatcat_id参数,(3)pagemaster模块的PAGE_id参数,(4)search的PDA_limit参数,和(5)可能其他calendar,fatcat,和pagemaster模块中的参数执行任意web脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/8393/info
 
PHP Website is a web site content management system that allows for easy maintainance and administration of interactive community-driven websites.
 
Cross-site vulnerabilities have been reported in the Calendar, PageMaster, Search and Fatcat modules that allow an attacker to create a link containing malicious script code that may be rendered in a user's browser when the link is followed.
 
This would occur in the security context of the site running PHP Website.

http://www.example.com/[PATH]/index.php?
module=pagemaster&PAGE_user_op=view_page&PAGE_id=10">[XSS ATTACK CODE]
&MMN_position=[X:X]
|受影响的产品
phpWebsite Phpwebsite 0.9
|参考资料

来源:US-CERTVulnerabilityNote:VU#664422
名称:VU#664422
链接:http://www.kb.cert.org/vuls/id/664422
来源:BUGTRAQ
名称:20030902GLSA:phpwebsite(200309-03)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106252188522715&w=2
来源:BUGTRAQ
名称:20030810phpWebSiteSQLInjection&DoS&XSSVulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106062021711496&w=2