Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Invision Community 安全特征问题漏洞
Vulnerability Description
Invision Community是美国Invision公司的一个用于设计、开发移动应用UI的软件。 Invision Community 中存在安全特征问题漏洞,该漏洞源于产品的mt_rand function函数可实现对上传文件的暴力攻击从而可预测文件名。攻击者可通过该漏洞执行客户端代码。以下产品及版本受到影响:Invision Community 4.6.5.1 之前版本。
CVSS Information
N/A
Vulnerability Type
N/A