2012/02/15ã JVN ãã JVN#35256978: cforms II ã«ãããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®èå¼±æ§ ãå ¬éããã¾ãããããã¯ã¯ã¬ã¸ããããã¦ããã¨ãããæµ·èåã¨ãååã®æ¸¡è¾ºåªä¹åãå¤åä¸ã«çºè¦ããèå¼±æ§ã§ãã èå¼±æ§èªä½ã¯ã©ãã«ã§ããããããªæ®éã® XSS ã§ãããå®ã¯ãã®èå¼±æ§ã 2010 å¹´ 10 æã« exploit ã³ã¼ããå ¬éããããããã 1 å¹´ 4 ã¶æå¾ã® 2012 å¹´ 2 æã¾ã§ä¿®æ£çãæä¾ããã¦ããªãã£ããã®ã§ãã ãã®ãããªå±éºãªç¶æ ãé·æéç¶ãã¦ããã®ã«ã¯ãæ§ã ãªçç±ãããã¾ããããã§ã¯ããã®èª¬æã¨ãã©ãããã°äºæ ãé²ãããã¨ãããã¨ã«ã¤ãã¦æ¤è¨ãããã¨æãã¾ãã èå¼±æ§ã®æ¦è¦ æ¬é¡ã«å ¥ãåã«ã主㫠cforms II ã®ã¦ã¼ã¶åãã«èå¼±æ§èªä½ã®æ¦è¦ã«ã¤ãã¦ãã£ãã説æãã¾ããåè¿°ã®ã¨ãããæªä¿®æ£ã®ç¶æ ã§ exploit ã³ã¼ããå ¬é


{{#tags}}- {{label}}
{{/tags}}