Multiple security vulnerabilities in a commercial system of trs

Source: Internet
Author: User

Trs has multiple vulnerabilities in a commercial system, including information leakage, unauthorized access to xss, and other trs was40 products. unauthorized access direct access to was40/tree can see some background functions 2. information Leakage access was40/passwd/passwd.htm input a user name that does not exist will expose the server's intranet IP address and the possibility of brute force password cracking. 3. the submitted data is not filtered when unauthorized publishing information + xss editing information, and user logon verification is not performed. 4. some user systems have system/manager. If the email system does not restrict cookie domains, this xss vulnerability will have a greater impact.Solution:Add permissions to some was40 files. filter user submitted data. Delete the demo page and data that comes with the system according to business needs.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.