Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in 2z project 0.9.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) contentshort or (2) contentfull parameter in an addnews action to the default URI; (3) the content parameter in a pm write action to 2z/admin.php; (4) the referer parameter to templates/default/usermenu.tpl, accessed through index.php; or the (5) newavatar or (6) newphoto parameter in a profile action to the default URI under 2z/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
2z Project 多个跨站脚本漏洞
Vulnerability Description
2z project存在多个跨站脚本漏洞。远程攻击者可以借助多个方式,注入任意Web脚本或者HTML代码。这些方式包含:(1) contentshort(2)contentfull中默认的URI;(3)2z/admin.php中content参数的一个写于操作(4)通过index.php的templates/default/usermenu.tpl参数提交;(5) newavatar(6)2z中策略设置中新图像参数的缺省URI。
CVSS Information
N/A
Vulnerability Type
N/A