Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG element.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
nc-cms 跨站脚本漏洞
Vulnerability Description
nc-cms是一套基于PHP的可嵌入式轻量级CMS(内容管理系统)。 nc-cms 2017-03-10及之前版本中的index.php?action=edit_html页面存在跨站脚本漏洞。远程攻击者可借助‘name’参数利用该漏洞注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A