Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Informix Web DataBlade SQL查询语句HTML条目自动解码漏洞
Vulnerability Description
Informix是由IBM发布和维护的企业级数据库产品,其中Informix Web DataBlade是连接Informix数据库和Web服务器的接口。 Informix Web DataBlade在对HTML编码的字符串处理存在漏洞,可导致远程攻击者以informax进程执行任意SQL查询语句,造成数据库破坏等攻击。 HTML编码的字符串当使用在SQL查询中会自动解码,开发者一般会使用$(WEBUNHTML)来检查所有用户输入,WDB会使用$(WEBUNHTML)函数来转换<>"&字符为HTML条目,
CVSS Information
N/A
Vulnerability Type
N/A