Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft internet information server 跨站脚本漏洞
Vulnerability Description
Microsoft internet information server 存在安全漏洞,该漏洞源于Microsoft IIS在处理帮助文件搜索功能时没有很好的检查用户输入,可以导致攻击者进行跨站脚本执行攻击。当IIS在处理帮助文件搜索功能时,没有对搜索引擎字段数据进行充分检查,攻击者可以在搜索引擎字段中输入包含恶意脚本代码的链接并返回给浏览此连接的客户端,如果客户端信任此WEB站点,包含在链接中的恶意脚本代码就会在用户浏览器上执行,导致跨站脚本攻击。可能导致攻击获得用户基于Cookie认证的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A