KKE Info Media Kmita Catalogue 'search.php' 跨站脚本攻击漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1116510 漏洞类型 跨站脚本
发布时间 2008-10-28 更新时间 2008-11-13
CVE编号 CVE-2008-5067 CNNVD-ID CNNVD-200811-223
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/32543
https://www.securityfocus.com/bid/80823
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200811-223
|漏洞详情
KmitaCatalogue中的search.php存在跨站脚本攻击漏洞。远程攻击者可以借助q参数,注入任意的web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/31968/info

Kmita Catalogue is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

Kmita Catalogue V2 is vulnerable; other versions may also be affected. 

http://www.example.com/search.php?q=<script>alert(document.cookie);</script>&Search=Search
|受影响的产品
Kkeim Kmita Catalogue 2.0
|参考资料

来源:BID
名称:31968
链接:http://www.securityfocus.com/bid/31968
来源:OSVDB
名称:49441
链接:http://www.osvdb.org/49441
来源:SECUNIA
名称:32457
链接:http://secunia.com/advisories/32457