漏洞标题
N/A
漏洞描述信息
"Address Book 1.04e中的多个SQL注入漏洞允许远程攻击者通过(1)Lastname,(2)Firstname,(3)PasswordOld,(4)PasswordNew,(5)Id,(6)Language,(7)DefaultLetter,(8)NewUserPassword,(9)NewUserType,(10)NewUserEmail参数在(a)user.php中执行任意SQL命令;在(b)search.php中的(11)GoTo和(12)Search参数;以及在(c)save.php中的(13)GroupAddName参数。"
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the (11) goTo and (12) search parameters in (b) search.php; and the (13) groupAddName parameter in (c) save.php.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
The Address Book 多个SQL注入漏洞
漏洞描述信息
The Address Book 1.04e存在多个SQL注入漏洞,远程攻击者可以通过在(a)user.php内的(1)lastname,(2)firstname,(3)passwordOld,(4)passwordNew,(5)id,(6)language,(7)defaultLetter,(8)newuserPass,(9)newuserType,(10)newuserEmail参数;在(b)search.php内的(11)goTo和(12)search参数;和在(c)save.php内的(13)gr
CVSS信息
N/A
漏洞类别
SQL注入