CVE-2007-0364
nicecoder.com 的 INDEXU 5.3 及更早版本中存在多个跨站脚本(XSS)漏洞,远程攻击者可通过以下参数注入任意 Web 脚本或 HTML:(1) 传递给 (a) suggest_category.php 的 error_msg 参数;(2) 传递给 (b) user_detail.php 的...
- 已发布
- 2007年1月19日
- 已更新
- 2024年8月7日
- 分配 CNA
- mitre
- 观察到的证据
- 2007年1月16日
初级CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N低 · 未来 30 天
- 百分位
- 85.5%
- 型号日期
- 2026年9月21日
EPSS 是统计估计,而不是确定性或影响衡量标准。将其与 CVSS、KEV 状态、暴露程度和您的环境相结合。
总结
nicecoder.com 的 INDEXU 5.3 及更早版本中存在多个跨站脚本(XSS)漏洞,远程攻击者可通过以下参数注入任意 Web 脚本或 HTML:(1) 传递给 (a) suggest_category.php 的 error_msg 参数;(2) 传递给 (b) user_detail.php 的 u 参数;(3) 传递给 (c) tell_friend.php 的 friend_name、(4) friend_email、(5) error_msg、(6) my_name、(7) my_email 和 (8) id 参数;(9) 传递给 (d) sendmail.php 的 error_msg、(10) email、(11) name 和 (12) subject 参数;(13) 传递给 (e) send_pwd.php 的 email、(14) error_msg 和 (15) username 参数;(16) 传递给 (f) search.php 的 keyword 参数;(17) 传递给 (g) register.php 的 error_msg、(18) username、(19) password、(20) password2 和 (21) email 参数;(22) 传递给 (h) power_search.php 的 url、(23) contact_name 和 (24) email 参数;(25) 传递给 (i) new.php 的 path 和 (26) total 参数;(27) 传递给 (j) modify.php 的 query 参数;(28) 传递给 (k) login.php 的 error_msg 参数;(29) 传递给 (l) mailing_list.php 的 error_msg 和 (30) email 参数;(31) 传递给 (m) upgrade.php 的 gateway 参数;以及另一个未指明的攻击向量。
来源
12SwEET-DeViL · php · 2007年1月16日
负责任的使用
仅在您拥有或有权测试的系统上使用漏洞信息。 Kitploit 链接到公共研究元数据,并且不存储漏洞代码或恶意负载。