漏洞信息详情
Drupal Deleted Input Format 跨站脚本攻击漏洞
漏洞简介
Drupal是一个开放源码的网站内容管理系统(CMS)平台。
Drupal在删除输入格式时,没有充分的删除与内容过滤相关的所有内容。远程攻击者可以利用未明向量,执行跨站脚本攻击。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Drupal
Drupal 6.1
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal 5.10
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 5.12
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.8
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.1 revision 1.1
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.11
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.5
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.2
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 5.7
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 6.5
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 6.3
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 6.0
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 5.3
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal Drupal 6.2
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal Drupal 5.9
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 5.1
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 6.6
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal 5.0
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 5.6
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
Drupal 6.4
Drupal drupal-6.7.tar.gz
http://ftp.drupal.org/files/projects/drupal-6.7.tar.gz
Drupal 5.4
Drupal drupal-5.13.tar.gz
http://ftp.drupal.org/files/projects/drupal-5.13.tar.gz
参考网址
来源: drupal.org
链接:http://drupal.org/node/345441
来源: FEDORA
名称: FEDORA-2008-11213
链接:https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00767.html
来源: FEDORA
名称: FEDORA-2008-11196
链接:https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00740.html
来源: XF
名称: drupal-htmltags-xss(47259)
链接:http://xforce.iss.net/xforce/xfdb/47259
来源: VUPEN
名称: ADV-2008-3414
链接:http://www.vupen.com/english/advisories/2008/3414
来源: OSVDB
名称: 50662
链接:http://www.osvdb.org/50662
来源: SECUNIA
名称: 33147
链接:http://secunia.com/advisories/33147
来源: SECUNIA
名称: 33112
链接:http://secunia.com/advisories/33112
受影响实体
- Drupal Drupal:5.2<!--2000-1-1-->
- Drupal Drupal:5.1<!--2000-1-1-->
- Drupal Drupal:5.0<!--2000-1-1-->
- Drupal Drupal:5.3<!--2000-1-1-->
- Drupal Drupal:5.6<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...