Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier versions allows remote attackers to inject arbitrary web script or HTML via the username parameter to comment.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
glfusion 'lib-comment.php'跨站脚本攻击漏洞
Vulnerability Description
glfusion是一款开放源码的基于PHP开发的内容管理系统(CMS)。 glFusion 1.1.0,1.1.1及之前版本中的lib-comment.php里的匿名评论特性存在跨站脚本攻击漏洞。远程攻击者可以借助到comment.php的用户名参数,注入任意的web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A