CNCVE编号:CNCVE-20020026 CVE编号: 安全级别:中 漏洞中文描述: OpenBB是一个基于Web的论坛程序,用PHP实现,可运行于Unix类操作系统下,也可运行于Windows平台。OpenBB对用户输入过滤上存在漏洞,可能使远程攻击者利用在论坛上的发贴对其他用户进行跨站脚本执行攻击。OpenBB支持用户在贴子中使用标记插入图像,但它未对标记中的内容做充分的过滤,这可能导致攻击者在此标记的内容中放入脚本代码,当用户浏览相关页面时,脚本将在用户的浏览器中执行。攻击者可能借此得到用户基于Cookie的认证信息。 漏洞英文描述: OpenBB is web forum software written in PHP. It will run on most Linux and Unix variants, in addition to Microsoft Windows operating systems. OpenBB allows users to include images in forum messages using image tags, with the following syntax:
url of image It is possible to inject arbitrary script code into forum messages via these image tags. Script code will be executed in the browser of the user viewing the forum message, in the context of the website running the vulnerable software. This may allow an attacker to steal cookie-based authentication credentials. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0272.html http://www.openbb.net/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误