Title:Zend Server Zend Debugger 跨站脚本漏洞 (CVE-2018-10230) Description:Zend Server是美国Zend技术公司的一款PHP Web开发应用服务器,它简化了Windows和Linux环境中PHP应用程序的开发和运行。Zend Debugger是其中的一个调试工具。 Zend Server 9.1.3之前版本中的Zend Debugger存在跨站脚本漏洞,该漏洞源于程序在使用错误消息中用户控制的数据之前,没有正确的编码该数据。远程攻击者可通过在服务器响应中构建任意的HTML元素利用该漏洞在用户浏览器中执行任意的JavaScript代码。
Description
Zend Server before version 9.13 is vulnerable to cross-site scripting via the debug_host parameter.
File Snapshot
id: CVE-2018-10230
info:
name: Zend Server <9.13 - Cross-Site Scripting
author: marcos_iaf
se
...
Shenlong Bot has cached this for you
Remarks
1. It is advised to access via the original source first.2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.