Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design Storesprite before 7 - 19-06-14, when using the currency selection dropdown, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to brand.php, related to the currencyUrl function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lamp Design Storesprite 跨站脚本漏洞
Vulnerability Description
Lamp Design Storesprite是英国Lamp Design公司的一套免费的基于PHP和MySQL的购物车程序,它包括顾客忠诚度、顾客评分和评论、状态提醒、订单跟踪等模块。 Lamp Design Storesprite 7 - 19-06-14之前的版本中的templates/defaultheader.php文件存在跨站脚本漏洞,该漏洞源于brand.php脚本没有充分过滤‘PATH_INFO’参数。远程攻击者可利用该漏洞注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A