Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter to the /register URI, because the jQuery prepend() method is used.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Trape 跨站脚本漏洞
Vulnerability Description
Trape是一套开源的互联网跟踪识别工具。该工具能够对会话进行远程识别,模拟钓鱼攻击。 Trape 2019-05-08及之前版本中的static/js/trape.js文件存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
CVSS Information
N/A
Vulnerability Type
N/A