漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.37, USG FLEX series firmware versions 5.00 through 5.37, USG FLEX 50(W) series firmware versions 5.10 through 5.37, USG20(W)-VPN series firmware versions 5.10 through 5.37, and VPN series firmware versions 5.00 through 5.37, could allow an unauthenticated LAN-based attacker to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed to steal cookies when the user visits the specific CGI used for dumping ZTP logs.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Zyxel ATP 跨站脚本漏洞
Vulnerability Description
Zyxel ATP是中国合勤(Zyxel)公司的一款防火墙。 Zyxel ATP 存在跨站脚本漏洞,该漏洞源于CGI程序中存在跨站脚本(XSS)漏洞。受影响的产品和版本:Zyxel ATP series 5.10至5.37版本,USG FLEX series 5.00至5.37版本,USG FLEX 50(W) series 5.10至5.37版本,USG20(W)-VPN series 5.10至5.37版本,VPN series 5.00至5.37版本。
CVSS Information
N/A
Vulnerability Type
N/A