Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ViewCVS跨站脚本执行漏洞
Vulnerability Description
ViewCVS是一款查看CVS系统的脚本,可使用在Unix和Linux操作系统下,也可使用在Microsoft Windows操作系统下。 ViewCVS对用户提供的数据未进行正确充分的检查,可导致远程攻击者进行跨站脚本执行攻击。 其中viewcvs.cgi对用户提供给URL的数据缺少过滤,攻击者可以在运行ViewCVS系统的站点上构建包含恶意代码的URL链接,当论坛用户浏览此包含恶意代码的链接时,就可以导致脚本代码在浏览用户浏览器中执行,使攻击者获得用户基于Cookie认证的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A