Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Nuke SQL注入漏洞
Vulnerability Description
PHP-Nuke 7.8 Patched 3.2之前的版本中存在SQL注入漏洞。远程攻击者可以借助查询字符串中经过编码的/%2a (/*)序列(会绕过用于防止SQL注入的正则表达式)执行任意SQL命令,如通过kala参数演示的那样。
CVSS Information
N/A
Vulnerability Type
N/A