Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Github yclas 跨站脚本漏洞
Vulnerability Description
Github yclas是个功能强大的脚本,可以在几秒钟内将任何域转换为完全可定制的分类广告站点。 Yclas4.3.0版本存在跨站脚本漏洞,该漏洞源于软件中的install/view/form.php对于SITE_NAME参数没有进行有效的验证和转义,攻击者可利用该漏洞可数据库中实现存储型跨站脚本漏洞。
CVSS Information
N/A
Vulnerability Type
N/A