漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Stored Cross‑Site Scripting in Link Aggregation Name Handling
Vulnerability Description
A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create a trunk entry containing malicious HTML/JavaScript code. When the affected page is viewed, the injected script executes in the context of the victim’s browser, enabling unauthorized actions such as interface manipulation. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Phoenix Contact多款产品 跨站脚本漏洞
Vulnerability Description
PHOENIX CONTACT FL SWITCH和PHOENIX CONTACT FL NAT都是德国菲尼克斯电气(PHOENIX CONTACT)公司的产品。PHOENIX CONTACT FL SWITCH是一款工业级以太网交换机。PHOENIX CONTACT FL NAT是一系列工业安全网关。 Phoenix Contact多款产品存在跨站脚本漏洞,该漏洞源于Link Aggregation配置界面,可能导致未经验证的远程攻击者注入恶意脚本,从而执行未经授权的操作。以下产品受到影响:FL NAT
CVSS Information
N/A
Vulnerability Type
N/A