Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2) subquery parameters to the newbb plus module, the forum parameter to (3) newtopic.php, (4) edit.php, or (5) reply.php in the newbb plus module, or (6) the msg_id parameter to print.php in the messages module.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RunCMS 多个SQL注入漏洞
Vulnerability Description
RunCMS是一套基于PHP的内容管理系统(CMS)。 RunCMS的实现上存在多个输入验证漏洞,远程攻击者可能利用此漏洞非授权访问数据库。RunCMS对多个脚本的没有对用户请求参数数据做充分的检查过滤,远程攻击者可能在数据中插入特定的SQL语句序列从而对数据库执行授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A