Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Smoothwall Express 3.1 'modem.cgi' Cross-Site Scripting
Vulnerability Description
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted payloads in parameters like INIT, HANGUP, SPEAKER_ON, SPEAKER_OFF, TONE_DIAL, and PULSE_DIAL to execute arbitrary JavaScript in users' browsers when the stored data is retrieved.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Smoothwall Express 跨站脚本漏洞
Vulnerability Description
Smoothwall Express是Smoothwall开源的一个基于GNU/Linux的防火墙操作系统。 Smoothwall Express 3.1-SP4-polar-x86_64-update9版本存在跨站脚本漏洞,该漏洞源于modem.cgi脚本对INIT、HANGUP、SPEAKER_ON、SPEAKER_OFF、TONE_DIAL和PULSE_DIAL等参数输入验证不足,可能导致存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A