Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPKIT多个跨站脚本漏洞
Vulnerability Description
PHPKIT是一套基于Web的内容管理系统(CMS)。该系统提供论坛、留言板等模块。 PHPKIT 1.6.1 R2及更早版本中的多个跨站脚本漏洞,可让远程攻击者通过以下方式注入任意Web脚本或HTML:(1) login/profile.php、(2) login/userinfo.php、(3) admin/admin.php和(4) imcenter.php中的多个矢量,以及(5)引用站点统计信息,(6) HTML标题元素和(7)论坛发布中的徽标alt属性,以及(8)Guestbook中的主页字段。
CVSS Information
N/A
Vulnerability Type
N/A