Bludit CMS <= 3.20.0 - Cross-Site Scripting
Bludit CMS contains a reflected XSS caused by improper sanitization in the search plugin, letting unauthenticated attackers inject arbitrary JavaScript, exploit requires crafted malicious search query.
Bludit 是一款轻量级、简单、快速且易于使用的开源内容管理系统 (CMS)。它非常适合快速搭建个人博客、公司网站、项目主页或任何其他类型的网站。Bludit 具有许多特性,包括易于使用、简单、快速、安全、灵活、可定制、轻量级、搜索引擎友好等。
共找到 4 条公开漏洞记录
Bludit CMS contains a reflected XSS caused by improper sanitization in the search plugin, letting unauthenticated attackers inject arbitrary JavaScript, exploit requires crafted malicious search query.
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.