Multiple Vendor CGI Script Forced...

- AV AC AU C I A
发布: 2001-06-13
修订: 2025-04-13

Many web-based applications, (ie, threaded discussion forums) contain security vulnerabilities which can improperly allow an attacker to force other, possibly authenticated users, to submit arbitrary method GET requests. Many such CGI applications will accept user input in the form of HTML-embedded references to images and other web content. For example, forum scripts may allow users to include images in discussion threads, by supplying a URL pointing to the appropriate image file. It has been discovered that in many cases, users can supply hostile querystrings concealed within posted image references. When, for example, a forum user clicks on a posted image link, the hostile querystring contained within the <img> tag will be unknowingly submitted by the target user. If the exploited user is already authenticated, for instance as a forum administrator, the attacker-supplied CGI query can be carried out with the target user's apparent permission. This could allow an attacker to...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息