Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in submit.php in PHP-Fusion 6.0.204 allows remote attackers to inject arbitrary web script or HTML via nested tags in the news_body parameter, as demonstrated by elements such as "<me<meta>ta" and "<sc<script>ript>".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Fusion submit.php 跨站脚本攻击漏洞
Vulnerability Description
PHP-Fusion 6.0.204中的submit.php存在跨站脚本攻击漏洞,远程攻击者可以通过在news_body参数中嵌套的标签来注入任意web参数或HTML,如通过"<me<meta>ta"和"<sc<script>ript>"这样的元素。
CVSS Information
N/A
Vulnerability Type
N/A