Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) to_p_dict or (2) to_r_list parameter. NOTE: this issue might be related to the htmlarea plugin and CVE-2013-5670.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WikiWig Xinha编辑器跨站脚本漏洞
Vulnerability Description
WikiWig是一套采用PHP和MySQL搭建的Wiki引擎。Xinha是一款所见即所得HTML编辑器,它提供文件管理、图片上传、图片编辑等功能。 WikiWig 5.01版本中使用的Xinha编辑器中的SpellChecker模块中存在跨站脚本漏洞,该漏洞源于spell-check-savedicts.php脚本没有充分过滤to_p_dict和to_r_list参数。远程攻击者可通过构造特制的URL利用该漏洞注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A