Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Yasna Yazd Discussion Forum 多个跨站脚本攻击漏洞
Vulnerability Description
Yasna Yazd Discussion Forum是一个基于Java开发的开源论坛程序。 Yazd Forum Software 3.x存在多个跨站脚本攻击漏洞。远程攻击者可以借助(1) 对(a) search.jsp的q参数, 和 (2)对(b) error.jsp 和 (c) userAccount.jsp的msg参数,注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A