链接:http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2253 *>测试方法: --------------------------------------------------------------------------------警 告以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!vendor ()提供了如下测试方法: Original report:"if logged in and go to linkhttp://<wwwroot>/group/members.php?id=2&query=123"%22%3E%3Cscript%3Ealert(1)%3C/script%3Exssthen xss"参考自 https://bugs.launchpad.net/mahara/+bug/1079498建议: -------------------------------------------------------------------------------- 厂商补丁:mahara ------ https://mahara.org/tracker/ https://bugs.launchpad.net/mahara/+bug/1079498Mahara 单击劫持攻击漏洞FreeBSD Linux兼容层本地权限提升漏洞相关资讯 Mahara Mahara安全漏洞