漏洞信息详情
FuseTalk ComFinish.CFM 多个跨站脚本攻击漏洞
漏洞简介
FuseTalk ComFinish.CFM 中存在多个跨站脚本攻击漏洞。远程攻击者可以借助提交到(a)forum/include/error/autherror.cfm的(1)FTVAR_LINKP和(2)FTVAR_URLP参数以及到(b)forum/include/common/comfinish.cfm和(c)blog/include/common/comfinish.cfm的(3)FTVAR_SCRIPTRUN参数,注入任意的web脚本或HTML。
漏洞公告
参考网址
来源: XF
名称: fusetalk-comfinish-autherror-xss(34955)
链接:http://xforce.iss.net/xforce/xfdb/34955
来源: BID
名称: 24564
链接:http://www.securityfocus.com/bid/24564
来源: BID
名称: 24563
链接:http://www.securityfocus.com/bid/24563
来源: BUGTRAQ
名称: 20070620 fusetalk CSS (autherror.cfm)
链接:http://www.securityfocus.com/archive/1/archive/1/471853/100/0/threaded
来源: BUGTRAQ
名称: 20070620 fusetalk CSS (comfinish.cfm)
链接:http://www.securityfocus.com/archive/1/archive/1/471846/100/0/threaded
来源: OSVDB
名称: 37143
链接:http://osvdb.org/37143
来源: OSVDB
名称: 37142
链接:http://osvdb.org/37142
来源: OSVDB
名称: 37141
链接:http://osvdb.org/37141
来源: SREASON
名称: 2842
链接:http://securityreason.com/securityalert/2842
来源: SECUNIA
名称: 25707
链接:http://secunia.com/advisories/25707
受影响实体
- Fusetalk Fusetalk:4.0:-:Coldfusion<!--2000-1-1-->
- Fusetalk Fusetalk:4.0:-:Enterprise<!--2000-1-1-->
- Fusetalk Fusetalk:3.0:-:Standard<!--2000-1-1-->
- Fusetalk Fusetalk:2.0:-:Basic<!--2000-1-1-->
- Fusetalk Fusetalk:2.0:-:Coldfusion<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...