Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_assess action. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Myshell evalSMSI 'assess.php'跨站脚本攻击漏洞
Vulnerability Description
evalSMSI是用PHP/MySQL开发的WEB应用,用于评估信息安全管理系统。 evalsmsi的assess.php中存在跨站脚本攻击漏洞。远程攻击者可以借助向报表的标注框中注入JavaScript,执行存储式跨站脚本攻击,导致任意web脚本和HTML注入。
CVSS Information
N/A
Vulnerability Type
N/A