Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows remote National Rail Enquiries servers or man-in-the-middle attackers to inject arbitrary web script or HTML, and execute arbitrary code, via a response body, as demonstrated by a SCRIPT element that references a vbscript: URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
National Rail Enquiries Live Departure Boards Gadget跨站脚本攻击漏洞
Vulnerability Description
C1.1版本以前的National Rail Enquiries Live Departure Boards gadget中存在跨站脚本攻击漏洞,会允许National Rail Enquiries 服务器或中间人攻击者通过一个反应实体(例如,涉及一个vbscript:URI的一个SCRIPT元素),来执行任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A