Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the goform/zForm_save_changes sip_nick parameter. The password of alphaadmin for the admin account may be used for authentication in some cases.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zenitel Norway IP-StationWeb 跨站脚本漏洞
Vulnerability Description
Zenitel Norway IP-StationWeb 4.2.3.9之前版本中存在跨站脚本漏洞。远程攻击者可借助Station Status或Account Settings界面中的Display Name字段利用该漏洞注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A