漏洞信息详情
ECW-Shop Cat参数跨站脚本漏洞
漏洞简介
ECW-Shop 5.5版本的index.php存在跨站脚本漏洞。远程攻击者可以借助cat参数注入任意web脚本或HTML。
漏洞公告
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] .
参考网址
来源: XF 名称: ecwshop-cat-xss(14032) 链接:http://xforce.iss.net/xforce/xfdb/14032 来源: BID 名称: 9244 链接:http://www.securityfocus.com/bid/9244 来源: www.securiteam.com 链接:http://www.securiteam.com/unixfocus/6D00F2A95C.html 来源: SECTRACK 名称: 1008522 链接:http://securitytracker.com/id?1008522 来源: SECUNIA 名称: 10458 链接:http://secunia.com/advisories/10458
受影响实体
- Ecw-Shop Ecw-Shop:5.5<!--2000-1-1-->
- Ecw-Shop Ecw-Shop:5.01<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...