Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients via (1) search.php and (2) the "Your name" field during account registration.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mambo Site Server帐号注册过程HTML标记注入漏洞
Vulnerability Description
Mambo Site Server是一款免费开放源代码WEB内容管理工具,由PHP编写。 Mambo Site Server在帐号注册过程中没有对用户输入中可能出现HTML标记进行充分过滤,远程攻击者可能利用此漏洞进行跨站脚本执行攻击。 攻击者可能在提交给"Your Name"表单的参数串中插入任意的HTML标记或某些恶意的脚本代码,当其他用户查看攻击者相关的信息时,可能导致跨站脚本执行。
CVSS Information
N/A
Vulnerability Type
N/A