全面网络扫描器VB源代码 很实用

源代码在线查看: yabb gold 1 prior sp 1.3.2 multiple input validation.plugin

软件大小: 1036 K
上传用户: xx87293767
关键词: 网络 扫描器 源代码
下载地址: 免注册下载 普通下载 VIP

相关代码

				329
				YaBB Gold 1 prior SP 1.3.2 multiple input validation
				CGI
				2005/01/09
				Marc Ruef
				marc.ruef at computec.ch
				http://www.computec.ch
				computec.ch
				Marc Ruef
				marc.ruef at computec.ch
				http://www.computec.ch
				computec.ch
				2005/01/09
				1.1
				Renamed the plugin file name, name and title in 1.1
				tcp
				80
				open|send GET /YaBB.pl HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# 200 *Powered by.*YaBB 1 Gold - *
				75
				The NASL script is Copyright (C) 2004 Tenable Network Security
				YaBB Gold 1
				The pattern matching is not so accurate.
				Unknown
				The remote host is using the YaBB 1 Gold web forum software. According to its version number, the remote version of this software is vulnerable to various input validation issues which may allow an attacker to perform a cross site scripting attack or an HTTP splitting  attack against the remote host.
				Upgrade to YaBB 1 Gold SP 1.3.2 or newer.
				Approx. 30 minutes
				Maybe
				http://www.securityfocus.com/bid/11235/exploit/
				Yes
				Yes
				Medium
				6
				6
				8
				7
				Medium
				Nessus can check this flaw with the plugin 14806 (YaBB Gold 1 Multiple Input Validation Issues).
				11235
				14806
				Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
				http://www.computec.ch
				
				
							

相关资源