CNCVE编号:CNCVE-20020052 CVE编号: 安全级别:高 漏洞中文描述: Prospero Message Boards是一个基于web的信息系统,提供社区和论坛的功能。Prospero Message Boards没有过滤JavaScript命令。如果提交到Prospero论坛的HTML格式的消息包含有JavaScript命令,当其他用户浏览时,脚本的命令将会执行,从而引起一系列的跨站脚本执行攻击。Prospero使用了cookie来做用户验证,所以这个漏洞可能用来劫取用户帐号。 漏洞英文描述: Prospero Message Boards are a web based messaging system, supporting communities and forums. HTML formatted messages posted to Prospero forums may contain JavaScript commands. When viewed by another user, the script will be executed in the context of the forum web page. This may lead to a number of cross-agent scripting attacks. It has been reported that Prospero uses cookies for user authentication, opening the possibility that this vulnerability could be used to hijack user accounts. 漏洞参考: http://www.sentinelchicken.com/advisories/prospero/index.php?PRINTABLE=true http://www.cert.org/advisories/CA-2000-02.html http://www.prospero.com/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误