Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a "'" (single quote) in the scope parameter to do/view/TWiki/WebSearch.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TWiki 跨站脚本漏洞
Vulnerability Description
TWiki是美国软件开发者Peter Thoeny所研发的一套基于Perl语言的开源Wiki程序,是一个基于Web的网站协作平台,它可用于项目开发管理、文档管理、知识库管理以及其他协作工作。 TWiki 6.0.0版本和6.0.1版本的lib/TWiki.pm文件中的‘urlEncode’函数存在不完整的黑名单漏洞。远程攻击者可借助‘scope’参数中的单引号利用该漏洞实施跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A