Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the searchTerms parameter in an editArticleCategories operation (aka an admin category search).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LifeType searchTerms 在'admin.php'参数跨站脚本漏洞
Vulnerability Description
LifeType是一款开放源码的博客平台。 LifeType的admin.php文件中没有正确过滤searchTerms参数输入便返回给了管理员,如果将op设置为editArticleCategories的话,远程攻击者可以通过跨站脚本攻击导致在管理员浏览器会话环境中执行任意HTML和脚本代码。
CVSS Information
N/A
Vulnerability Type
N/A