漏洞信息详情
Mephistoles HTTPD跨站脚本漏洞
漏洞简介
Mephistoles httpd 0.6.0最终版存在跨站脚本(XSS)漏洞。远程攻击者可以通过向URL注入任意HTML或脚本像其他用户一样执行任意脚本。
漏洞公告
The vendor has released updates that address this issue. Please see the references for more information. Mephistoles Internet Suite HTTPD 0.6 p2
- Mephistoles Internet Suite Mephistoles 0.6.2.pre1 http://downloads.sourceforge.net/mephistoles/mephistoles-httpd-0.6.2pr e1-noarch.pl?modtime=1083628800&big_mirror=0
- Mephistoles Internet Suite Mephistoles 0.6.2.pre1 http://downloads.sourceforge.net/mephistoles/mephistoles-httpd-0.6.2pr e1-noarch.pl?modtime=1083628800&big_mirror=0
参考网址
来源: BID 名称: 9470 链接:http://www.securityfocus.com/bid/9470 来源: BUGTRAQ 名称: 20040121 Mephistoles Httpd 0.6.0final XSS 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107470433714179&w=2 来源: XF 名称: mephistoles-httpd-xss(14899) 链接:http://xforce.iss.net/xforce/xfdb/14899 来源: OSVDB 名称: 3689 链接:http://www.osvdb.org/3689 来源: SECUNIA 名称: 10693 链接:http://secunia.com/advisories/10693
受影响实体
- Mephistoles_internet_suite Mephistoles_httpd:0.6_p2<!--2000-1-1-->
- Mephistoles_internet_suite Mephistoles_httpd:0.6_p1<!--2000-1-1-->
- Mephistoles_internet_suite Mephistoles_httpd:0.6_final<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...