Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TWIG Webmail 的 SQL Query 可更改漏洞
Vulnerability Description
CVE(CAN) ID: CAN-2001-1348 对 SQL 查询语句,SQL 查询串(query string)没有用单引号括起来是一个小小的错误。这个错误可能导致潜在的危险。TWIG Webmail 存有这个漏洞。 如我们所知的,如果域类型是 int、mediumint、tinyint 等诸如此类的,SQL 查询串没有用单引号括起来能够被 mysql 接受。比如,下面两个语句的效果一样: DELETE FROM mytable WHERE id='1' AND owner='karet' DELE
CVSS Information
N/A
Vulnerability Type
N/A