漏洞信息详情
WebCT的校园版HTML注入漏洞
漏洞简介
WebCT Campus Edition 4.1.1.5版本存在跨站脚本攻击(XSS)漏洞。远程攻击者借助CSS样式标签中的@import URL函数注入任意web脚本或HTML。
漏洞公告
The vendor has released WebCT CE 4.1 SP2 Hotfix 40832, WebCT CE 4.0 SP3 Hotfix 40833 and WebCT CE 3.8.4 Hotfix 8 to address this issue. WebCT WebCT Campus Edition 3.8
- WebCT CE 3.8.4 Hotfix 8 http://download.webct.com/ce+/3.8/hotfixes/384_hotfix_rel_notes.html
- WebCT CE 3.8.4 Hotfix 8 http://download.webct.com/ce+/3.8/hotfixes/384_hotfix_rel_notes.html
- WebCT CE 4.0 SP3 Hotfix 40833 http://download.webct.com/ce+/4.0/hotfixes/40sp3_hotfix_rel_notes.html
- WebCT CE 4.1 SP2 Hotfix 40832 http://download.webct.com/ce+/4.1/hotfixes/41sp2_hotfix_rel_notes.html
- WebCT CE 4.1 SP2 Hotfix 40832 http://download.webct.com/ce+/4.1/hotfixes/41sp2_hotfix_rel_notes.html
参考网址
来源: XF 名称: webct-import-xss(15652) 链接:http://xforce.iss.net/xforce/xfdb/15652 来源: BID 名称: 9999 链接:http://www.securityfocus.com/bid/9999 来源: BUGTRAQ 名称: 20040329 WebCT Campus Edition 4.1 - Cross site scripting using CSS @import 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108057915916365&w=2 来源: SECUNIA 名称: 11242 链接:http://secunia.com/advisories/11242
受影响实体
- Webct Webct:Campus_4.1.1.5<!--2000-1-1-->
- Webct Webct:Campus_4.1<!--2000-1-1-->
- Webct Webct:Campus_4.0<!--2000-1-1-->
- Webct Webct:Campus_3.8.4<!--2000-1-1-->
- Webct Webct:Campus_3.8<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...