Xoops Viewtopic.php Cross-Site...

- AV AC AU C I A
发布: 2004-01-26
修订: 2025-04-13

It has been reported that Xoops may be prone to a cross-site scripting vulnerability that may allow a remote user to execute HTML or script code in a user's browser. HTML and script code may be parsed via the 'topic_id' and 'forum' URI parameters of 'newbb/viewtopic.php' script. Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible. Xoops versions 2.x have been reported to be prone to this issue.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息