XOOPS-magazine
Hauptmenu
Sidebar Navigation
Kategorien
Monatsarchive
RSS Feed
suck my

Breadcrumbs: Startseite

Social-Bookmarks
 

XOOPS 2.2.5 - cross-site scripting vulnerability

english.gif german.gif

XOOPS 2.2.5 - cross-site scripting vulnerabilityXOOPS 2.2.5

Risk Level:
MEDIUM - Vulnerability can be exploited to execute arbitrary HTML and script code in a user’s browser session in the context of an affected site.

Cross-site Scripting Vulnerability:
Input passed via the URL to “register.php” in the “/modules/profile” directory isn’t properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.

Sample Exploit Code:

http://host/xoops/modules/profile/register.php?>'"><script>alert('XSS');</script>

The DigiTrust Group

2 Kommentare

  1. Kommentar von Rene Sato:

    XOOPS 2.2.5 Security Fix Release:
    http://downloads.sourceforge.net/xoops/xoops-2.2.5-security.zip

  2. Kommentar von Omer Singer:

    The original advisory can be found at: http://www.digitrustgroup.com/advisories/web-application-security-xoops.html

Einen Kommentar hinterlassen

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

Oh no, I cannot read this. Please, generate a

Powered by XOOPS 2.0.16 © 2001-2007 The XOOPS Project

Design by XOOPS-magazine.com Powered by XOOPS 2.0.16 | Ref: 1220636394
Impressum / Disclaimer Impressum | Kontakt / Contact Kontakt | Xoops Headlines all Xoops-Headlines | Xoops Headlines Sitemap | Xoops Headlines Stats

Admin-Infos: 0.78 Sekunden / secounds + 3 Abfragen / queries
Special thanks to Link > matchan matchan and Link > kruxmux kruxmux!



xoops topliste