Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MKPortal跨站脚本攻击及SQL注入漏洞
Vulnerability Description
MKPortal是一款免费的主站/内容管理系统,可无缝的集成于大多数流行的论坛软件。 MKPortal的index.php文件的ind参数存在SQL注入漏洞。此外,pm_popup.php的u1、m1、m2、m3、m4参数中没有正确过滤用户输入,存在跨站脚本攻击漏洞。攻击者可以利用这些漏洞远程执行任意代码
CVSS Information
N/A
Vulnerability Type
N/A