Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and (2) Text fields; (3) the gallery, possibly the Description field in Your Pictures; (4) the forum, possibly the Your Message field when posting a new thread; or (5) the vote parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Qsoft-Inc qsoft k-rate - premium跨站脚本攻击漏洞
Vulnerability Description
Qsoft K-Rate Premium中存在多个跨站脚本攻击漏洞。远程攻击者可以借助blog中可能的(1)标题和(2)文本字段;(3)画廊,可能是您图片中的描绘字段;(4)forum,可能是在粘贴一条新线时您的信息字段;或(5)一个查看操作中对index.php的投票参数,注入任意的web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A