Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the year parameter to modules/kalender.php, (2) the Page parameter in a List action to modules/ereignis.php, (3) the Kontext parameter in a Search action to modules/kategorie.php, or (4) the image parameter to modules/image.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
collector.ch myColex SQL注入和跨站脚本攻击漏洞
Vulnerability Description
myColex是一款开放源码的在线博物馆及个人收藏网站的构建工具。 myColex 1.4.2版本中存在多个跨站脚本攻击漏洞。远程攻击者可以借助(1)对modules/kalender.php的年参数,(2)对modules/ereignis.php的一个列表操作的页参数,(3)对modules/kategorie.php的一个搜索操作中的Kontext参数,或(4)对modules/image.php的图像参数,注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A