漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ETicket Open.PHP 跨站脚本攻击漏洞
Vulnerability Description
ETicket Open.PHP中存在跨站脚本攻击漏洞。当register_globals被启用时,远程攻击者可以借助(1)错误和(2)警告参数,注入任意的web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A