osCommerce 2.2 Milestone 2 Update 060817中的多个跨站脚本攻击漏洞,远程攻击者可以通过(1)在(a)banner_manager.php,(b)banner_statistics.php,(c)countries.php,(d)currencies.php,(e)languages.php,(f)manufacturers.php,(g)newsletters.php,(h)orders_status.php,(i)products_attributes.php,(j)products_expected.php,(k)reviews.php,(l)specials.php,(m)stats_products_purchased.php,(n)stats_products_viewed.php,(o)tax_classes.php,(p)tax_rates.php或(q)/admin下zones.php脚本中的page参数,以及(2)在(r)admin/geo_zones.php中的zpage参数来注入任意的Web脚本或HTML。
osCommerce 2.2 Milestone 2 Update 060817中的多个跨站脚本攻击漏洞,远程攻击者可以通过(1)在(a)banner_manager.php,(b)banner_statistics.php,(c)countries.php,(d)currencies.php,(e)languages.php,(f)manufacturers.php,(g)newsletters.php,(h)orders_status.php,(i)products_attributes.php,(j)products_expected.php,(k)reviews.php,(l)specials.php,(m)stats_products_purchased.php,(n)stats_products_viewed.php,(o)tax_classes.php,(p)tax_rates.php或(q)/admin下zones.php脚本中的page参数,以及(2)在(r)admin/geo_zones.php中的zpage参数来注入任意的Web脚本或HTML。