Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
nuz007 smsboom dy.php cross site scripting
Vulnerability Description
A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is an unknown function of the file dy.php. Performing manipulation of the argument hm results in cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
smsboom 代码注入漏洞
Vulnerability Description
smsboom是QuitDropdatabaseFalse个人开发者的一个短信轰炸软件。 smsboom 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674及之前版本存在代码注入漏洞,该漏洞源于对文件dy.php中参数hm的错误操作,可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A