Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Namazu 字符编码 跨站脚本攻击漏洞
Vulnerability Description
Namazu是一款开源全文检索引擎。 Namazu 2.0.13及之前版本的namazu.cgi存在跨站点脚本攻击(XSS)漏洞。 远程攻击者可以借助一个以Tab符("%09") 开头的查询,绕过对查询串的检测,从而注入任意的HTML和web脚本。
CVSS Information
N/A
Vulnerability Type
N/A