Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the return parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Myshell evalSMSI 'ajax.php' 跨站脚本攻击漏洞
Vulnerability Description
evalSMSI是用PHP/MySQL开发的WEB应用,用于评估信息安全管理系统。 evalSMSI的脚本ajax.php中存在跨站脚本攻击漏洞。远程攻击者可以借助return参数,执行跨站脚本攻击,导致任意web脚本或HTML注入。注意:该漏洞来源未知,详细信息来源于第三方。
CVSS Information
N/A
Vulnerability Type
N/A