Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the sajax_get_common_js function in php/Sajax.php in Sajax 0.12 allows remote attackers to inject arbitrary web script or HTML via the URL parameter, which is not properly handled when using browsers that do not URL-encode requests, such as Internet Explorer 6. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
modernmethod Sajax'php/Sajax.php' 跨站脚本攻击漏洞
Vulnerability Description
AJAX(Asynchronous JavaScript and XML是指一种创建交互式网页应用的网页开发技术,Sajax是modernmethod公司基于AJAX技术开发的一种网页开发框架。 Sajax 0.12版本中的php/Sajax.php里的sajax_get_common_js函数存在跨站脚本攻击漏洞。远程攻击者可以借助URL参数,注入任意的web脚本或HTML。 当使用不对请求进行URL编码的浏览器时,比如IE6,该URL参数得不到正确的处理。
CVSS Information
N/A
Vulnerability Type
N/A