Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tipo or (2) destino parameter to login_registrese.php3 in the Services section, (3) the rubro parameter to precios.php3 in the Products section, (4) the arti parameter to recomenda_articulo.php3 in the Products section, (5) the descrip parameter in a profile action to control/abm_det.php3 in the e-Commerce section, (6) the tit parameter in a delivery_courier action to control/abm_list.php3 in the e-Commerce section, or (7) the tit parameter in an usuario action to control/abm_det.php3 in the e-Commerce section.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TornadoStore多个跨站脚本攻击漏洞
Vulnerability Description
TornadoStore 1.4.3以及早期版本存在多个跨站脚本攻击漏洞。远程攻击者可以借助(1)tipo或者(2)服务模块的login_registrese.php3的destino参数,(3)产品模块的precios.php3的rubro参数,(4)产品模块的recomenda_articulo.php3的arti参数,(5)电子商务模块的control/abm_det.php3配置文件操作中的descrip参数,(6)电子商务模块的control/abm_list.php3 delivery_cou
CVSS Information
N/A
Vulnerability Type
N/A