Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.16280
Kategorie:Web application abuses
Titel:vBulletin XSS(3)
Zusammenfassung:The remote version of vBulletin seems to be; prior or equal to version 2.3.5 or 3.0.5. These versions are vulnerable to a; cross-site scripting issue, due to a failure of the application to properly; sanitize user-supplied URI input.
Beschreibung:Summary:
The remote version of vBulletin seems to be
prior or equal to version 2.3.5 or 3.0.5. These versions are vulnerable to a
cross-site scripting issue, due to a failure of the application to properly
sanitize user-supplied URI input.

Vulnerability Impact:
As a result of this vulnerability, it is possible
for a remote attacker to create a malicious link containing script code that will
be executed in the browser of an unsuspecting user when followed.

This may facilitate the theft of cookie-based authentication credentials
as well as other attacks.

Solution:
Upgrade to version 2.3.6 or 3.0.6.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

CopyrightThis script is Copyright (C) 2005 David Maciejak

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.