漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP
Vulnerability Description
Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
SOTESHOP 跨站脚本漏洞
Vulnerability Description
SOTESHOP是SOTESHOP公司的一个网上商店系统。 SOTESHOP 8.3.4版本存在跨站脚本漏洞,该漏洞源于对adsTracker/checkAds中id参数处理不当,可能导致攻击者在受害者浏览器中执行JavaScript代码,窃取用户敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A