Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct function, and (2) the Type or Category values in a New entry, which is not properly handled in an error message by the submit_elog function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ELOG Nonexistent elogd.c 跨站脚本攻击漏洞
Vulnerability Description
ELOG中的elogd.c存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可通过(1)用作下载的文件名(send_file_direct 函数在出错信息内引用),和(2)在新条目内的Type或Category值(submit_elog函数未在出错信息内正确处理),注入任意HTML或Web脚本。
CVSS Information
N/A
Vulnerability Type
N/A