Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenWrt和LEDE 跨站脚本漏洞
Vulnerability Description
OpenWrt和LEDE都是针对嵌入式设备的Linux操作系统。该系统能够提供完全可写的文件系统和包管理。 OpenWrt 18.06.1及之前版本和LEDE 17.01及之前版本中的‘cgi_handle_request’函数存在跨站脚本漏洞。远程攻击者可利用该漏洞注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A