Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CafeLog b2 Weblog工具存在多个漏洞漏洞
Vulnerability Description
"b2"是由CafeLog开发的一款WEB日志工具。 "b2" WEB日志工具存在多个漏洞,远程攻击者可以利用这个漏洞进行命令执行、数据库操作、跨站脚本执行攻击。 "b2" WEB日志工具存在多个变量作为HTML属性数据返回到客户端WEB浏览器时没有进行正确检查,可导致攻击者进行跨站脚本执行攻击。 "b2" WEB日志工具中多处引用"tableposts"变量时没有过滤,如果系统没有设置"magic_quotes_gpc"为"on"的情况下,可导致SQL插入攻击,不过由于PHP mysql_query()
CVSS Information
N/A
Vulnerability Type
N/A