漏洞标题
N/A
漏洞描述信息
在 osCommerce 2.2 Milestone 2 Update 060817 中,多个跨站点脚本(XSS)漏洞允许远程攻击者通过 (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php 或 (q) zones.php 脚本中的 (1) 页面参数,以及 (r) admin/geo_zones.php 中的 (2) zpage 参数,允许攻击者注入任意的网页脚本或 HTML。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
osCommerce多个跨站脚本攻击漏洞
漏洞描述信息
osCommerce 2.2 Milestone 2 Update 060817中的多个跨站脚本攻击漏洞,远程攻击者可以通过(1)在(a)banner_manager.php,(b)banner_statistics.php,(c)countries.php,(d)currencies.php,(e)languages.php,(f)manufacturers.php,(g)newsletters.php,(h)orders_status.php,(i)products_attributes.php,(j
CVSS信息
N/A
漏洞类别
跨站脚本