Skip to main content
x

Workpress Framework ၏ Category Grid View Gallery Plugin မှနေ၍ Cross-Site-Scripting Vulnerability ဖြစ်စေနိုင်သောအကြောင်

Workpress Framework ၏ Category Grid View Gallery Plugin မှနေ၍ Cross-Site-Scripting Vulnerability ဖြစ်စေနိုင်သော အကြောင်းနှင့် ပတ်သက်သည့် အချက်အလက်များကို ၂ဝ၁၃ ခုနှစ် ဇူလိုင်လ ၈ ရက်နေ့က SecurityFocus တွင် ထုတ်ပြန်အသိပေးခဲ့ကြောင်း သိရှိရပါသည်။ ၄င်း Vulnerability ကိုအသုံးပြု၍ Attacker များမှ User ၏ browser တွင် Arbitrary Script Code ကို execute လုပ်ခြင်းဖြင့် Browser မှတဆင့် Affected ဖြစ်သွားပြီးနောက်တွင် User ၏ Credentials Cookie-Based Authentication များကို ခိုးယူသွားနိုင်ကြောင်း တွေ့ရှိရပါသည်။
အသေးစိတ်ရှင်းလင်းချက်များနှင့် ဖြေရှင်းရန်နည်းလမ်းများကို အောက်ပါ Link တွင် ကြည့်ရှုနိုင်ပါသည်။

http://www.securityfocus.com/bid/60905/info