Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Faq-O-Matic跨站脚本执行漏洞
Vulnerability Description
PostCalendar 3.0是一款提供可交互事件日历的PHP-NUKE的模块程序,用户可以增加任意条目,可运行在多种Linux和Unix操作系统下。 PostCalendar 3.0对用户提交的数据没有正确充分的处理,导致攻击者可以进行跨站脚本攻击。 攻击者在登录系统后,提交一明文形式的事件,进行预览处理,然后插入任意脚本代码,再发送。当其他用户查看你的事件时候,脚本将会在用户浏览器上执行,导致基于Cookie认证的信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A