Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Greenbone Networks Greenbone Security Assistant charts模块跨站脚本漏洞
Vulnerability Description
Greenbone Networks Greenbone Security Assistant(GSA)是德国Greenbone Networks公司的一个提供访问OpenVAS服务层的Web接口。charts是其中的一个图表模块。 Greenbone Networks GSA 6.0.8之前6.x版本的charts模块中存在跨站脚本漏洞,该漏洞源于/opm URI没有充分过滤get_aggregat命令中的‘aggregate_type’参数。远程攻击者可利用该漏洞注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A