Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2) search parameter to Grid.fwx.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
fotoware fotoweb 跨站脚本攻击漏洞
Vulnerability Description
FotoWeb 是针对网站发布内容包括文档、图片、pdf、视频等实现归档的工具。 FotoWeb 6.0 (Build 273)版本中存在多个跨站脚本攻击漏洞。远程攻击者可以借助(1)对cmdrequest/Login.fwx的s参数和(2)对Grid.fwx的搜索参数,注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A