漏洞标题
北京 Baichuo Smart S85F 管理 Platform 导入html.php命令漏洞
漏洞描述信息
拜佐罗Smart S85F管理平台importhtml.php命令注入
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
Byzoro Smart S85F Management Platform importhtml.php command injection
漏洞描述信息
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown processing of the file importhtml.php. The manipulation of the argument sql leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235967. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
在命令中使用的特殊元素转义处理不恰当(命令注入)
漏洞标题
Beijing Baichuo Smart S85F Management Platform 命令注入漏洞
漏洞描述信息
Beijing Baichuo Smart S85F Management Platform是Beijing Baichuo公司的一个管理平台。 Beijing Baichuo Smart S85F Management Platform 20230722及之前版本存在命令注入漏洞,该漏洞源于文件importhtml.php的参数sql存在SQL注入漏洞。
CVSS信息
N/A
漏洞类别
命令注入