首页 网络安全 安全学院 查看内容

Game-Panel 存在跨站漏洞

2006-3-9 00:11 769 0

摘要: Game-Panel "message" Variable Handling Cross Site Scripting Vulnerability Technical Description ...
关键词: Vulnerability Scripting FrSIRT Panel exploited attackers Game affected english message

Game-Panel "message" Variable Handling Cross Site Scripting Vulnerability Technical Description A vulnerability has been identified in Game-Panel, which may be exploited by attackers to execute arbitrary scripting code. This flaw is due to an input validation error in the "login.php" script that does not properly validate the "message" parameter, which could be exploited by attackers to cause malicious scripting code to be executed by the user's browser in the security context of an affected Web site. Affected Products Game-Panel version 2.6.1 and prior Solution The FrSIRT is not aware of any official supplied patch for this issue. References http://www.frsirt.com/english/advisories/2006/0864 http://www.frsirt.com/english/reference/6923 Credits Vulnerability reported by retard, kim, and sycko.
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部