Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An XSS issue was discovered in Sandoba CP:Shop v2016.1. The vulnerability is located in the `admin.php` file of the `./cpshop/` module. Remote attackers are able to inject their own script codes to the client-side requested vulnerable web-application parameters. The attack vector of the vulnerability is non-persistent and the request method to inject/execute is GET with the path, search, rename, or dir parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sandoba CP:Shop ‘./cpshop/’模块跨站脚本漏洞
Vulnerability Description
Sandoba CP:Shop是德国Sandoba公司的一套在线商店系统。该系统销售管理、财务管理和站内搜索等功能。 Sandoba CP:Shop 2016.1版本中的‘./cpshop/’模块的‘admin.php’文件存在跨站脚本漏洞。远程攻击者可借助GET参数‘path’、‘search’、‘rename’或‘dir’参数利用该漏洞注入脚本代码。
CVSS Information
N/A
Vulnerability Type
N/A