漏洞信息详情
JSPWiki跨站脚本漏洞
漏洞简介
JSPWiki 2.1.120-cvs及之前版本中的Search.jsp存在跨站脚本(XSS)漏洞。远程攻击者可以像其他用户借助query参数来执行任意web脚本。
漏洞公告
The vendor has released version 2.1.123 to address this issue. Please note that this release is directly from the CVS repository from the project, and may not be stable. JSPWiki JSPWiki 2.1.120
- JSPWiki JSPWiki-latest.zip http://www.ecyrd.com/~jalkanen/JSPWiki/nightly/JSPWiki-latest.zip
- JSPWiki JSPWiki-latest.zip http://www.ecyrd.com/~jalkanen/JSPWiki/nightly/JSPWiki-latest.zip
- JSPWiki JSPWiki-latest.zip http://www.ecyrd.com/~jalkanen/JSPWiki/nightly/JSPWiki-latest.zip
参考网址
来源: XF 名称: jspwiki-query-xss(18236) 链接:http://xforce.iss.net/xforce/xfdb/18236 来源: BID 名称: 11746 链接:http://www.securityfocus.com/bid/11746 来源: SECUNIA 名称: 13285 链接:http://secunia.com/advisories/13285/ 来源: BUGTRAQ 名称: 20041124 STG Security Advisory: [SSA-20041122-11] JSPWiki XSS vulnerability 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110135663220831&w=2
受影响实体
- Jspwiki Jspwiki:2.1.122<!--2000-1-1-->
- Jspwiki Jspwiki:2.1.121<!--2000-1-1-->
- Jspwiki Jspwiki:2.1.120<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...