Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Invision Power Board Search.PHP "st" SQL注入漏洞
Vulnerability Description
Invision Power Board是一款基于WEB的论坛程序。 Invision Power Board包含的"sources/search.php"脚本对用户提交的URI参数缺少充分过滤,远程攻击者可以利用这个漏洞进行SQL注入攻击,可修改数据库或者获得敏感信息。 "sources/search.php"脚本对用户提交给"st"的参数缺少充分过滤,提交包含恶意SQL代码的数据给这个参数,可更改原有数据库逻辑, 导致敏感信息泄露或者数据库被更改。
CVSS Information
N/A
Vulnerability Type
N/A