Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Smoothwall Express 3.1 'time.cgi' Cross-Site Scripting
Vulnerability Description
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the NTP_SERVER parameter. Attackers can send POST requests to the time.cgi endpoint with script payloads in the NTP_SERVER parameter to execute arbitrary JavaScript in users' browsers.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Smoothwall Express 安全漏洞
Vulnerability Description
Smoothwall Express是Smoothwall开源的一个基于GNU/Linux的防火墙操作系统。 Smoothwall Express 3.1-SP4-polar-x86_64-update9版本存在安全漏洞,该漏洞源于time.cgi端点中NTP_SERVER参数操作不当,可能导致未经验证攻击者在用户浏览器中执行任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A