Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_member_id, year, agid, day, day_s, hour, minute, month, month_s, and year_s parameters in calendar.php, (4) the cid parameter in contents.php, (5) the dcp5_member_id parameter in forums.php, (6) the bid parameter in go.php, (7) the lid parameter in golink.php, (8) the dcp5_member_id and mid parameters in inbox.php, (9) the catid, dcat, and dl parameters in index.php, (10) the dcp5_member_id in informer.php, (11) the nid parameter in news.php, (12) the type and rate parameters in rate.php, (13) the q parameter in search.php, and (14) the dcp5_member_id in update.php. NOTE: other vectors in the PHP-CHECKER report are also covered by CVE-2005-3365 and CVE-2005-0454.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DCP-Portal多个跨站脚本和SQL注入漏洞
Vulnerability Description
DCP-Portal是一款网站内容管理系统,包括成员管理、投票系统、日历系统等。 DCP-Portal的calendar.php、register.php、index.php等脚本没有充分的验证POST变量,导致跨站脚本和SQL注入攻击,成功利用这些漏洞的攻击者可以远程执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A