Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Battleaxe Software BTTLXE Forum Login.ASP SQL注入漏洞
Vulnerability Description
bttlxeForum是一款基于EWB的论坛程序,由ASP实现。 bttlxeForum包含的'login.asp'对外部提供的数据缺少充分过滤,远程攻击者可以利用这个漏洞无需验证访问应用程序。 软件对用户提供的用户名和密码字段(可能其他字段)缺少正确的过滤,没有删除一些SQL命令字符,就直接提交给数据库解析,攻击者提交包含恶意SQL命令的用户名和字段,可以绕过验证,直接访问应用系统。
CVSS Information
N/A
Vulnerability Type
N/A