Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Z-BlogPHP 1.5.2 has a stored Cross Site Scripting Vulnerability exploitable by an administrator who navigates to "Web site settings --> Basic setting --> Website title" and enters an XSS payload via the zb_system/cmd.php ZC_BLOG_NAME parameter. NOTE: the vendor disputes the security relevance, noting it is "just a functional bug.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Z-BlogPHP 跨站脚本漏洞
Vulnerability Description
Z-BlogPHP是由Z-Blog社区开发的一套开源的基于PHP的博客系统。 Z-BlogPHP 1.5.2版本中的网站设置上的基础设置的网站标题字段存在跨站脚本漏洞。远程攻击者可借助‘ZC_BLOG_NAME’参数利用该漏洞注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A