Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires administrator privileges, and entering JavaScript is supported functionality
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
nc-cms 跨站脚本漏洞
Vulnerability Description
nc-cms是一套基于PHP的可嵌入式轻量级CMS(内容管理系统)。 nc-cms 2017-03-10及之前版本中的index.php?action=edit_html&name=home_content URI存在跨站脚本漏洞。远程攻击者可借助HTML Source Editor利用该漏洞注入恶意的JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A