Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
https-nj.gov---CVE-2018-14040 — تقرير الثغرات للموقع الرسمي لنيوجيرسي | Kitploit
أدوات/GitHubGitHub/snorlyd/https-nj.gov---cve-2018-14040
التحليل الثابتتحليل الثغرات الأمنيةتحليل الكودأمن الويبالأوراق والأبحاثالتعلم والتعليم
GitHubsnorlyd/https-nj.gov---cve-2018-14040

https-nj.gov---CVE-2018-14040

تقرير الثغرات للموقع الرسمي لنيوجيرسي

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع
1منذ 4 سنواتلم تتم المراجعة بعد

https-nj.gov---CVE-2018-14040

تقرير الثغرة الأمنية في الموقع الرسمي لنيوجيرسي

في Bootstrap قبل الإصدار 4.1.2، يمكن حدوث XSS في سمة بيانات الطي الرئيسية. سمتا data-target وdata-parent معرضتان لهجمات البرمجة النصية عبر المواقع (Cross-Site Scripting).

<script src="https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js"></script>

<script src="http://maxcdn.bootstrapcdn.com/bootstrap/3.3.6/js/bootstrap.min.js"></script>

<button data-toggle="collapse" data-target="">Test</button>

التوصية

يمكن أن يكون إصلاح هذه المشكلة المحددة هو تغيير دالة getTargetFromTrigger:

return $(target) إلى:

return $(document.querySelector(target)) ولكن يبدو أن المشكلة نفسها موجودة في أماكن أخرى أيضًا.

فيما يلي مثال آخر:

<a href="" data-dismiss="alert">Test</a>

المراجع

http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html http://seclists.org/fulldisclosure/2019/May/10 http://seclists.org/fulldisclosure/2019/May/11 http://seclists.org/fulldisclosure/2019/May/13 https://access.redhat.com/errata/RHSA-2019:1456 https://blog.getbootstrap.com/2018/07/12/bootstrap-4-1-2/ https://github.com/twbs/bootstrap/issues/26423 https://github.com/twbs/bootstrap/issues/26627 https://github.com/twbs/bootstrap/pull/26630 https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e@%3Cdev.superset.apache.org%3E https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E https://lists.apache.org/thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714@%3Cissues.hbase.apache.org%3E

تنزيل الأداة
https://seclists.org/bugtraq/2019/May/18
https://www.oracle.com/security-alerts/cpuApr2021.html