漏洞信息详情

Namazu 'namazu.cgi'跨站脚本攻击漏洞

  • CNNVD编号:CNNVD-200803-377
  • 危害等级: 中危
  • CVE编号: CVE-2008-1468
  • 漏洞类型: 跨站脚本
  • 发布时间: 2008-03-24
  • 威胁类型: 远程
  • 更新时间: 2008-09-17
  • 厂        商: namazu
  • 漏洞来源: JPCERT/CC reported...

漏洞简介

Namazu 2.0.18之前的版本中的namazu.cgi存在跨站脚本攻击漏洞。远程攻击者借助编码过的UTF-7输入,注入任意的Web脚本或HTML。此漏洞与对charset的设置失败有关。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Namazu Project Namazu 2.0.10

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

Namazu Project Namazu 2.0.12

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

Namazu Project Namazu 2.0.13

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

Namazu Project Namazu 2.0.14

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

Namazu Project Namazu 2.0.17

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

Namazu Project Namazu 2.0.7

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

Namazu Project Namazu 2.0.8

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

Namazu Project Namazu 2.0.9

Namazu Project Namazu 2.0.18

http://namazu.org/#download">http://namazu.org/#download

参考网址

来源: www.namazu.org

链接:http://www.namazu.org/security.html.en

来源: SECUNIA

名称: 31687

链接:http://secunia.com/advisories/31687

来源: SECUNIA

名称: 29386

链接:http://secunia.com/advisories/29386

来源: SUSE

名称: SUSE-SR:2008:017

链接:http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html

来源: JVN

名称: JVN#00892830

链接:http://jvn.jp/jp/JVN%2300892830/index.html

来源: FEDORA

名称: FEDORA-2008-2767

链接:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00654.html

来源: FEDORA

名称: FEDORA-2008-2678

链接:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00575.html

来源: XF

名称: namazu-character-encoding-xss(41360)

链接:http://xforce.iss.net/xforce/xfdb/41360

来源: BID

名称: 28380

链接:http://www.securityfocus.com/bid/28380

来源: SECUNIA

名称: 29561

链接:http://secunia.com/advisories/29561

漏洞信息快速查询

相关漏洞

更多