Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Powie PForum Username跨站执行脚本漏洞
Vulnerability Description
Powie PForum是采用PHP和MySQL实现的WWW论坛,可运行于绝大多数Unix/Linux变体以及微软Windows操作系统。 PForum易受跨站执行脚本攻击。 尽管作者试图过滤来自URL请求的恶意代码,但它忘记检查username参数了。比如攻击者设法使受害者访问如下URL test@test.com&pwd=test&pwd2=test&filled=1" target="_blank">http://www.server.com/pforum/edituser.php?boardid=
CVSS Information
N/A
Vulnerability Type
N/A