Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
UBBThreads dosearch.php远程SQL注入漏洞
Vulnerability Description
UBBThreads是一款基于PHP的论坛程序。 UBBThreads dosearch.php脚本对用户提交的输入缺少充分过滤,远程攻击者可以利用这个漏洞进行SQL注入攻击,可能获得敏感信息。 dosearch.php不正确过滤用户提交给'name'参数的数据,远程攻击者提供恶意SQL命令作为参数数据,可更改原有SQL逻辑,获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A