漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ipl/web is vulnerable to reflected XSS by malformed search requests
Vulnerability Description
ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in versions 0.13.1 and 0.10.3.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Icinga PHP Library 跨站脚本漏洞
Vulnerability Description
Icinga PHP Library是Icinga开源的一个开源监控和度量解决方案系统的 Web 组件。 Icinga PHP Library 0.13.1之前版本存在跨站脚本漏洞,该漏洞源于允许攻击者将恶意Javascript注入受害者浏览器并在Icinga Web环境中运行,受害者需访问特制网站且可能无法立即注意到异常。
CVSS Information
N/A
Vulnerability Type
N/A