Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FreeWebStat多个跨站脚本攻击漏洞
Vulnerability Description
FreeWebStat 1.0 rev37存在多个跨站脚本攻击漏洞。 远程攻击者可以借助纳入pixel.php之前未净化的对pixel.php的(1) site, (2) jsref, (3) jsres, 和 (4) jscolor 参数,以及(5) 对stat.php的检索关键字,注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A