漏洞标题
N/A
漏洞描述信息
在ASP-DEV XM论坛 RC3中的论坛.asp中,跨站脚本(XSS)漏洞允许远程攻击者通过论坛_title参数注入任意的Web脚本或HTML。注意:这个问题的来源未知;详细信息仅从BID获得。此外,它的准确性有问题,因为XM论坛 RC3的源代码中并未指定"forum_title"。可能,但不能确定这是CVE-2004-2211。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID. In addition, its accuracy is in question because "forum_title" does not appear to be specified in the source code for XM Forum RC3. It is possible, but not certain, that this is CVE-2004-2211.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
ASP-DEV XM Forum Forum.ASP跨站脚本漏洞
漏洞描述信息
ASP-DEV XM Forum RC3的forum.asp中存在跨站脚本攻击漏洞,远程攻击者可以通过forum_title参数注入任意Web脚本或HTML。
CVSS信息
N/A
漏洞类别
跨站脚本