Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ASP-Nuke 'comment_post.asp'远程SQL注入漏洞
Vulnerability Description
ASP-Nuke是一款开放源码的软件应用,可在Web Server上运行基于社区的站点。 ASP-Nuke中存在SQL注入漏洞,远程攻击者可以利用此漏洞非授权访问数据库。 起因是没有正确的过滤用户输入。请看/module/support/task/comment_post.asp的第36行和第75行代码: <? ... nTaskID = steNForm("TaskID") ... If sErrorMsg = "" Then ' prevent dup posting here sStat = "SE
CVSS Information
N/A
Vulnerability Type
N/A