Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
YABB跨站脚本执行漏洞
Vulnerability Description
YaBB(Yet Another Bulletin Board)是一款免费开放源码的WEB论坛/社区程序,由PERL语言实现,可以运行在unix/linux、MacOS、Microsoft Windows 9x/ME/NT/2000/XP系统平台下。 YaBB对用户输入过滤上存在漏洞,可使远程攻击者利用在论坛上发贴对其他浏览用户进行跨站脚本执行攻击。 YaBB支持在帖子中用户使用[img][/img]标记插入图象连接,但它未对标记中的内容做充分过滤,这可能导致攻击者在此标记的内容中放入脚本代码,当其他用户
CVSS Information
N/A
Vulnerability Type
N/A