![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.16059 |
Categoría: | Web application abuses |
Título: | Zeroboard < 4.1pl5 Multiple Vulnerabilities - Active Check |
Resumen: | Zeroboard is prone to arbitrary PHP code execution and; cross-site scripting (XSS) vulnerabilities. |
Descripción: | Summary: Zeroboard is prone to arbitrary PHP code execution and cross-site scripting (XSS) vulnerabilities. Vulnerability Insight: The remote version of this software is vulnerable to XSS and remote script injection due to a lack of sanitization of user-supplied data. Vulnerability Impact: Successful exploitation of this issue may allow an attacker to execute arbitrary code on the remote host or to use it to perform an attack against third-party users. Affected Software/OS: Zeroboard prior to version 4.1pl5. Solution: Update to version 4.1pl5 or later. CVSS Score: 6.8 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-1419 BugTraq ID: 12103 http://www.securityfocus.com/bid/12103 Bugtraq: 20041224 STG Security Advisory: [SSA-20041220-16] PHP source injection and cross-site scripting vulnerabilities in ZeroBoard (Google Search) http://marc.info/?l=bugtraq&m=110391024404947&w=2 http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030224.html http://www.osvdb.org/12580 http://www.osvdb.org/12581 http://securitytracker.com/id?1012677 http://secunia.com/advisories/13649 XForce ISS Database: zeroboard-outlogin-file-include(18677) https://exchange.xforce.ibmcloud.com/vulnerabilities/18677 XForce ISS Database: zeroboard-write-file-include(18679) https://exchange.xforce.ibmcloud.com/vulnerabilities/18679 Common Vulnerability Exposure (CVE) ID: CVE-2004-2738 http://www.osvdb.org/12582 XForce ISS Database: zeroboard-checkuserid-xss(18680) https://exchange.xforce.ibmcloud.com/vulnerabilities/18680 |
Copyright | Copyright (C) 2004 David Maciejak |
Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |