Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Element-IT HTTP Commander 跨站脚本漏洞
Vulnerability Description
Element-IT HTTP Commander是德国Element-IT公司的托管在服务器上的基于 Web 的文件管理解决方案。它提供了处理文件的基本功能(创建、复制、删除等)和许多其他附加功能,例如与云服务的集成、直接在浏览器中在线编辑 Office 文档、标签、评论等。 Element-IT HTTP Commander 7.0.0版本存在安全漏洞,攻击者可利用该漏洞通过在用户代理字段中注入恶意脚本来获得管理访问权限。
CVSS Information
N/A
Vulnerability Type
N/A