Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-7202

EPSS 0.24% · P47
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-7202

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7_cendana-master/template/default/detail_template.php' and 'slims7_cendana-master/template/default-rtl/detail_template.php' URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
SLiMS 7 Cendana 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SLiMS 7 Cendana是一套开源的、免费的图书管理系统。 SLiMS 7 Cendana 2017-03-16之前的版本中存在跨站脚本漏洞,该漏洞源于程序没有充分过滤用户提交的数据。远程攻击者可利用该漏洞执行任意HTML和脚本代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-7202

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-7202

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-03-21 · 22 CVEs total

CVE-2017-6417多款Avira产品代码注入漏洞
CVE-2017-7210GNU Binutils 安全漏洞
CVE-2017-7209GNU Binutils 安全漏洞
CVE-2017-7208libav 安全漏洞
CVE-2017-7207Artifex Software Ghostscript 安全漏洞
CVE-2017-7206libav 安全漏洞
CVE-2017-7205GamePanelX-V3 跨站脚本漏洞
CVE-2017-7204imdbphp 跨站脚本漏洞
CVE-2017-7203ZoneMinder 跨站脚本漏洞
CVE-2017-7200OpenStack Glance Image Service API 安全漏洞
CVE-2014-9939GNU Binutils 缓冲区错误漏洞
CVE-2017-7215MISP 跨站脚本漏洞
CVE-2017-6186Bitdefender Total Security、Internet Security和Antivirus Plus 安全漏洞
CVE-2017-5567多款Avast产品安全漏洞
CVE-2017-5566AVG Ultimate、AVG Internet Security和AVG AntiVirus FREE 安全漏洞
CVE-2017-5565Trend Micro Maximum Security、Internet Security和和Antivirus+ Security 安全漏洞
CVE-2017-3850Cisco IOS和IOS XE Software 安全漏洞
CVE-2017-3849Cisco IOS和IOS XE Software 安全漏洞
CVE-2016-6650EMC RecoverPoint和EMC RecoverPoint for Virtual Machines 安全漏洞
CVE-2016-4504多款Meteocontrol WEB'log产品跨站请求伪造漏洞

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-7202

No comments yet


Leave a comment