积极预防 及时发现
快速响应 力保恢复
DCP-Portal是种内容管理系统,提供多种基于WEB方式的操作,比如更新站点、成员管理等等。DC...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020043 CVE编号: 安全级别:高 漏洞中文描述: DCP-Portal是种内容管理系统,提供多种基于WEB方式的操作,比如更新站点、成员管理等等。DCP-Portal存在跨站脚本执行漏洞。攻击者首先注册一个用户,然后访问http://www.dcp-portal_host/user_update.php ,修改自己的job info,在此插入任意代码,比如当其它用户察看攻击者的个人信息时,这些script脚本就会在用户浏览器中执行。 漏洞英文描述: DCP-Portal is a content management system which enables various web based updates. It enables an admin to remotely manage the entire site, and allows for members to submit news/content and reviews etc. A user of the DCP-Portal system is given the option to publish some profile information. It is possible to include JavaScript commands in some of this information. When the malicious user is viewed by a third party, these script commands will execute within the context of the DCP-Portal page, leading to a cross-agent scripting attack. It has been demonstrated that the job information field suffers from this vulnerability. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0164.html http://www.dcp-portal.com/ 系统类型:其他 漏洞类型:输入有效性检查错误