关于 CVE-2005-0040 的漏洞信息

1. 漏洞描述
From NVD
Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.
From 神龙GPT (AIGC)
在DotNetNuke 3.0.12之前,多个跨站脚本(XSS)漏洞允许远程攻击者通过(1)注册新的用户页面、(2)用户代理或(3)用户名来 inject任意的 web 脚本或 HTML,这些漏洞在发送到错误日志之前未正确括号。
2. 漏洞评分(CVSS)
From NVD
NVD 暂无评分
From 神龙GPT (AIGC)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
3. 漏洞类别
From NVD
NVD 暂无漏洞类别信息
From 神龙GPT (AIGC)
神龙GPT 暂无漏洞类别信息(请耐心等待)
Reference