Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DMANews多个SQL注入漏洞
Vulnerability Description
DMANews 0.904和0.910的index.php 中存在多个SQL注入漏洞。远程攻击者可以借助(1)comments action 中的 id参数和thenews_list action中的 (2) sortorder和(3) display_num 参数,执行任意的SQL指令。
CVSS Information
N/A
Vulnerability Type
N/A