Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver1 1.4.6 and earlier, Ver1 Beta 1.5.0-beta and earlier, Ver2 2.1.2a and earlier, Ver2 Beta(RC) 2.1.1-beta and earlier, Community Edition 1.3.4 and earlier, and Community Edition Nightly-Build r17336 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4535 and CVE-2008-4536.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ec-cube 跨站脚本攻击漏洞
Vulnerability Description
EC-CUBE Ver1, Ver1 Beta, Ver2, Ver2 Beta(RC), Community Edition, 以及Community Edition Nightly-Build r17336 及其早期版本中存在跨站脚本攻击漏洞。远程攻击者可以通过未明向量来执行任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A