Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Aztek Forum HTML注入漏洞
Vulnerability Description
Aztek Forum 4.0可以让远程攻击者通过在index.php的msg参数中的一个"*/*"获取敏感信息,因其在一条MySQL出错信息中暴露了用户名和口令,可能是由于一条强制SQL错误或SQL注入的缘故。
CVSS Information
N/A
Vulnerability Type
N/A