Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LimeSurvey 不完整黑名单漏洞
Vulnerability Description
LimeSurvey(前称PHPSurveyor)是LimeSurvey团队开发的一套开源的在线问卷调查程序,它支持调查程序开发、调查问卷发布以及数据收集等功能。 LimeSurvey 2.05+ Build 140618版本的common_helper.php脚本中的‘autoEscape’函数存在不完整黑名单漏洞,该漏洞源于index.php脚本没有充分过滤‘loadname’参数中的CBK字符集。远程攻击者可利用该漏洞实施跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A