Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SonicWall SonicOS 跨站脚本漏洞
Vulnerability Description
Sonicwall SonicWall SonicOS是美国Sonicwall公司的一套专为SonicWall防火墙设备设计的操作系统。 SonicWALL SonicOS Enhanced 存在跨站脚本漏洞,该漏洞源于如果SonicWall的内容过滤规则阻断了用户访问站点的请求的话,就会向用户显示一个默认的错误页面。由于没有正确地执行过滤,攻击者可以创建特制的URL触发错误并在错误页面中注入恶意脚本。浏览器无法区分内容是来自所请求的站点还是设备,因此会导致在目标域的环境中注入脚本,并在用户查看错误页面时
CVSS Information
N/A
Vulnerability Type
N/A