Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) pass parameter to login.php, or the (3) name parameter to contact.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FlatPress 多个跨站脚本攻击漏洞
Vulnerability Description
FlatPress是一个开源,符合标准(XHTML valid),基于Smarty模板引擎的个人博客系统。支持多语言,支持通过插件来可扩展功能。 FlatPress 0.804中存在多个跨站脚本攻击漏洞。远程攻击者可以通过(1) 用户 或 (2) login.php的pass参数, 或者 (3)contact.php的名字参数,执行任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A