Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xoops WebChat远程SQL插入漏洞
Vulnerability Description
Xoops是一个用面向对象的PHP写的开源、免费的Web服务器程序,它用MySQL作为后台数据库,可以运行于大多数的Unix和Linux系统 Xoops的WebChat模块包含的index.php脚本对用户提交输入缺少正确过滤,远程攻击者可以利用这个漏洞进行SQL注入攻击,可以用来获得或破坏数据库信息。 WebChat模块包含的index.php脚本对用户提交的$roomid变量的数据缺少充分检查,攻击者可以构建恶意畸形查询字符串而导致修改原来系统的SQL查询逻辑,通过插入SQL代码到$roomid变量,
CVSS Information
N/A
Vulnerability Type
N/A