Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Total Shop UK eCommerce 跨站脚本漏洞
Vulnerability Description
Total Shop UK eCommerce中存在漏洞,可被恶意攻击者利用进行跨站脚本攻击。该漏洞源于传送到如index.php脚本中的URL的输入在返回给用户之前未经正确验证。攻击者可利用该漏洞在受影响站点上下文中用户浏览器会话中执行任意HTML和脚本代码。成功的攻击需要受害者使用未进行URL编码请求的浏览器(如Internet Explorer 6)。开源2.1.2_p1版本中存在漏洞,其他版本也可能受到影响。
CVSS Information
N/A
Vulnerability Type
N/A