Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Redmine Title参数跨站脚本漏洞
Vulnerability Description
Redmine是一套开源的基于Web的项目管理和缺陷跟踪工具。该工具提供项目管理、问题跟踪和基于角色的访问控制等功能。 Redmine没有正确地定义页面字符编码,将<title>放到了<meta>之前。攻击者可以创建标题编码为UTF-7 JavaScript的页面,当使用启用了自动选择功能的Internet Explorer查看该页面就会执行内嵌的代码。
CVSS Information
N/A
Vulnerability Type
N/A