Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, and (6) fromfromlist parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zorum index.php 多个SQL注入漏洞
Vulnerability Description
Zorum是一款用PHP实现的免费开源论坛程序。 Zorum处理用户请求时存在多个输入验证漏洞,远程攻击者可能利用此漏洞对服务器进行SQL注入攻击。 Zorum的index.php脚本没有正确的过滤用户输入中的offset、tid、fromid、sortby、fromfrommethod和fromfromlist参数,允许远程攻击者执行SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A