Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI. NOTE: the start parameter/search action is already covered by CVE-2006-1807, and the show parameter/top action is already covered by CVE-2006-1360.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Shalwan MusicBox Page参数SQL注入漏洞
Vulnerability Description
Shalwan MusicBox 2.3.4及之前版本存在SQL注入漏洞。远程攻击者可以借助顶级URI请求中的viewgallery操作中的page参数,执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A