EZ Publish Search Cross-Site...

- AV AC AU C I A
发布: 2003-03-18
修订: 2025-04-13

eZ publish is prone to cross-site scripting attacks. This is due to insufficient sanitization of data passed to the search facility via URI parameters. As a result, it is possible for a remote user to create a malicious link to a site hosting the vulnerable software which contains hostile HTML and script code. If the link is visited, the attacker-supplied script code and HTML may be interpreted by the user's web browser. This could allow for compromise of cookie-based credentials or other possible attacks. This issue was reported in eZ publish 2.2.7. Other versions may also be affected.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息