CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-9802 Apache Sling Cross-Site-Scripting Vulnerability

2017年8月29日 2333点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

Apache Sling is a web framework that uses a Java Content Repository, such as Apache Jackrabbit, to store and manage content.

The Javascript method Sling.evalString() uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings.

Affected Version:
org.apache.sling.servlets.post bundle up to 2.3.21

Detection Logic:
This QID checks for Apache Sling installations running with default credentials and that have vulnerable versions of Apache Sling Servlet post authentication.

漏洞危害

An unauthenticated, remote attacker could exploit this vulnerability to execute arbitrary Javascript code on victim's browser.

解决方案

Vendor has released an updated version org.apache.sling.servlets.post 2.3.22 to fix this issue. Refer to the SLING-7041 for more details on the vulnerability and patches.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

SLING-7041

0daybank

标签: 暂无
最后更新:2017年8月29日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me