Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Anthill存在跨站脚本执行漏洞
Vulnerability Description
Anthill是一款基于PHP开发的程序缺陷跟踪系统,可使用在Linux,unix或者Microsoft windows操作系统下。 Anthill系统对用户输入处理缺少充分的检查,可导致攻击者进行跨站脚本执行攻击。 Anthill系统中几乎所有信息可提交处都没有过滤HTML,JavaScript标记,攻击者可以在任意地方提交恶意JavaScript代码,当浏览用户查看包含恶意代码的链接时,就可以导致恶意代码在浏览用户浏览器上执行,导致基于Cookie的认证信息被泄露等攻击。
CVSS Information
N/A
Vulnerability Type
N/A