Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web script or HTML via the (1) sort parameter in index2.php, (2) item_id parameter in report.php, (3) search_term parameter (aka the "search box") in search_reviews.php, (4) the profile field in usercp/profile_edit1.php, and the (5) review field in review_form.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
5 Star Review 多个跨站脚本攻击(XSS)漏洞
Vulnerability Description
5 Star Review存在多个跨站脚本攻击(XSS)漏洞。远程攻击者可以借助(1)index2.php中的sort参数, (2)report.php中的item_id参数, (3)search_reviews.php中的search_term参数(又称"搜索框"), (4)usercp/profile_edit1.php中的profile字段,以及(5)review_form.php中的review字段,注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A