Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are also vulnerable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Paul Puzyrev and Sergei Larionov MiniBB 'bb_admin.php'模块跨站脚本执行漏洞
Vulnerability Description
MiniBB(全称Minimalistic Bulletin Board)是一套免费、开源的互联网论坛软件。该软件支持多种论坛样式、多界面语言、多时区、插件扩展等。 MiniBB的bb_admin.php文件中没有正确地过滤对whatus参数的输入便返回给了用户,攻击者可以通过提交恶意HTTP请求导致在用户浏览器会话中执行任意HTML和脚本代码。
CVSS Information
N/A
Vulnerability Type
N/A