Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in the send_write page of (a) index.php; (3) subject, and (4) images parameters to (b) calendar.php; (5) bid, (6) replying_msg, (7) subject, (8) body, and (9) mid parameters to (c) forums.php; (10) subject and (11) message parameters to (d) inbox.php; (12) subject_color and (13) email parameters to (e) lostpassword.php; and the (14) c_name, (15) content_inicial, and (16) cid parameters to (f) mycontents.php. NOTE: the calendar.php/day vector is already subsumed by CVE-2006-0220, and the calendar.php/month, calendar.php/year, and search.php/q parameters for calendar.php are already subsumed by CVE-2004-2511.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DCP-Portal门户网站多个跨站脚本攻击漏洞
Vulnerability Description
DCP-Portal 6.1.1及其早期版本中存在多个跨站脚本攻击(XSS)漏洞,当register_globals有效时,远程攻击者可以通过以下途径注入任意Web脚本或 HTML:(1)在文件页中的 its_url参数和(2)在(a)index.php的send_write页中的url参数;(3)主题,和(4)在(b)calendar.php中的图像参数;(5)出价,(6)replying_msg,(7)主题,(8)正文,和(9)在(c)forums.php中的mid参数;(10)主题和(11)在(d)
CVSS Information
N/A
Vulnerability Type
N/A