Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TWiki URLPARAM变量跨站脚本漏洞
Vulnerability Description
TWiki是一款灵活易用、功能强大的企业协作平台和知识管理系统。 %URLPARAM{}% TWiki变量是用于创建动态wiki内容和wiki应用的命令。如果未经正确的编码便在HTML表单字段值中使用了URLPARAM的话,就可能导致跨站脚本攻击攻击。例如: <input type="text&" name="city&" value="%URLPARAM{ "city" }%" /> 攻击者可以创建city URL参数,用双引号括起input value=""属性,然后添加其他属性。
CVSS Information
N/A
Vulnerability Type
N/A