lotusInject.txt...

- AV AC AU C I A
发布: 2004-10-27
修订: 2025-04-13

An attacker can bypass native Lotus Notes HTML encoding in a computed value by adding square brackets to the beginning and end of a field of the following types computed, computed for display, computed when composed or a computed text element, Injecting HTML and JavaScript as desired.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息