Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in the xn function in RockMongo 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) db parameter on the login page or (2) username parameter in a login.index action to index.php and other unspecified parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RockMongo ‘username’参数跨站脚本漏洞
Vulnerability Description
RockMongo是RockMongo团队开发的一套基于PHP5的MongoDB(数据库)管理工具。 RockMongo 1.1.5及之前的版本中的‘xn’函数中存在跨站脚本漏洞,该漏洞源于当‘action’设置为‘login.index’时,index.php脚本没有正确过滤‘username’参数。远程攻击者可利用该漏洞注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A