Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VBulletin Profile.PHP跨站脚本攻击漏洞
Vulnerability Description
vBulletin 3.5.1 中的editavatar页存在跨站脚本攻击漏洞,远程攻击者可以通过一个在远程avatar url 字段中的URL注入任意Web脚本或URL,其中URL会生成一个解析错误,并可能要求一个如.jpg的结尾扩展。
CVSS Information
N/A
Vulnerability Type
N/A