来源:自学PHP网 时间:2015-04-17 14:47 作者: 阅读:次
[导读] YGN Ethical Hacker Group (lists yehg net)Concrete CMS 5.4.1.1 = Cross Site Scripting1. 概述Concrete CMS 5.4.1.1及低版本脚本跨站缺陷2. 背景Concrete5 makes running a website ea......
YGN Ethical Hacker Group (lists yehg net) 1. 概述 Concrete CMS 5.4.1.1及低版本脚本跨站缺陷 2. 背景
Concrete5 makes running a website easy. Go to any page in your site, 3. 缺陷描述
The rcID parameter is not properly sanitized, which allows attacker to 4. 影响版本 <= 5.4.1.1 5. PROOF-OF-CONCEPT/EXPLOIT vulnerable parameter: rcID
<form action="http://[www.2cto.com]/Concrete/index.php/login/do_login/" 6. SOLUTION Upgrade to 5.4.2 or higher. 7. VENDOR
Concrete CMS Developers 8. CREDIT
This vulnerability was discovered by Aung Khant, http://yehg.net, YGN 9. DISCLOSURE TIME-LINE
2011-04-14: vulnerability reported 10. REFERENCES
Original Advisory URL: #yehg [2011-08-23] |
自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习
京ICP备14009008号-1@版权所有www.zixuephp.com
网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com