Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
tinyBB 多个输入验证漏洞
Vulnerability Description
tinyBB是一款简单小巧的开源论坛程序。 tinyBB的实现上存在多个输入验证漏洞,导致SQL注入等各种安全威胁。 tinyBB的footers.php文件没有正确过滤tinyBB.tinybb_footers变量,允许远程攻击者包含任意文件。有漏洞的代码在footers.php的第3行: 3: if (strlen($tinybb_footers) > 0) { require_once($tinybb_footers); } 此外,forgot.php.Parameter $q中存在SQL注入漏洞。
CVSS Information
N/A
Vulnerability Type
N/A