Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname). NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates, then this issue would not give any additional privileges, and thus would not be considered a vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
bBlog 跨站脚本漏洞
Vulnerability Description
bBlog 0.7.2版本的administration panel存在跨站脚本漏洞。具有超级用户特权的远程认证用户借助博客名称($blogname)注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A