Nokia Solutions and Networks... CVE-2015-6929 CNNVD-201509-197

4.3 AV AC AU C I A
发布: 2015-09-16
修订: 2015-11-24

Nokia Solutions and Networks(前称Nokia Siemens Networks)@vantage Commander是芬兰Nokia Solutions and Networks公司的一套用于帮助移动网络运行多服务的的解决方案。 Nokia Solutions and Networks @vantage Commander中存在多个跨站脚本漏洞,这些漏洞源于多个脚本没有充分过滤参数。远程攻击者可利用这些漏洞注入任意Web脚本或HTML。(cftraces/filter/fl_copy.jsp脚本没有充分过滤‘idFilter’和‘nameFilter’参数;cftraces/filter/fl_crea1.jsp脚本没有充分过滤‘flName’参数;cftraces/process/pr_show_process.jsp脚本没有充分过滤‘serchStatus’、‘refreshTime’和‘serchNode’参数;cftraces/session/se_crea.jsp脚本没有充分过滤多个参数(MaxActivationTime,NumberOfBytes,NumberOfTracefiles,SessionName,serchSessionkind);cftraces/session/se_show.jsp脚本没有充分过滤‘serchSessionDescription’参数;cftraces/session/tr_crea_filter.jsp脚本没有充分过滤‘serchApplication’和‘serchApplicationkind’参数;cftraces/session/tr_create_tagg_para.jsp脚本没有充分过滤多个参数(columKeyUnique,columParameter,componentName,criteria1,criteria2,criteria3,description,filter,id,pathName,tableName,component);home/certificate_association.jsp脚本没有充分过滤‘userid’参数。)

0%
暂无可用Exp或PoC
当前有1条受影响产品信息