漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Roller: Roller's weblog category, weblog settings and file-upload features did not properly sanitize input could be exploited to perform Reflected Cross Site Scripting (XSS) even on a Roller site configured for untrusted users.
Vulnerability Description
Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted users, then you need to do nothing because you trust your users to author raw HTML and other web content. If you are running with untrusted users then you should upgrade to Roller 6.1.2 and you should disable Roller's File Upload feature.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Apache Roller 跨站脚本漏洞
Vulnerability Description
Apache Roller是美国阿帕奇(Apache)基金会的一套基于Java的多用户开源博客系统。 Apache Roller 存在跨站脚本漏洞,该漏洞源于 Weblog Category 名称、网站关于信息和文件上传功能中发现了输入验证和清理不足的问题。
CVSS Information
N/A
Vulnerability Type
N/A