Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to login.asp, or (6) the email parameter to subscribe/default.asp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Express-Web Content Management System未明跨站脚本漏洞
Vulnerability Description
Express-Web Content Management System (CMS)中存在多个跨站脚本(XSS)漏洞。远程攻击者可以借助default.asp的(1)n、(2)b、(3)e或(4)a参数,(5)login.asp的HTTP请求中的Referer标题,或者(6)subscribe/default.asp的email参数窃取基于cookie的认证信息并且可能进行其他利用。
CVSS Information
N/A
Vulnerability Type
N/A