Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sun AnswerBook2多个安全漏洞
Vulnerability Description
Solaris是一款商业性质的操作系统。 在AnswerBook2 Server中发现了2个有关恶意HTML标记的漏洞。 1. AnswerBook2的搜索功能动态的生成web页面,这可能允许执行脚本,或向用户提供恶意的HTML。如果用户跟随了链接到AnswerBook2搜索结果的网页,邮件消息或新闻组张贴中不可信任的链接/URI的话,就可能在他们的浏览器中无意中执行远程普通用户编写的脚本。远程攻击者可以通过这些不可信任的链接/URI以访问链接/URI用户的权限执行任意命令。 2. AnswerBook2
CVSS Information
N/A
Vulnerability Type
N/A