Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Woltlab Burning Books 'addentry.php'Eval注入漏洞
Vulnerability Description
WoltLab Burning Book 1.1.2的addentry.php中存在Eval注入漏洞,远程攻击者可以通过精心编制的稍后由eval处理且在数据库存储了PHP代码的POST请求来执行任意PHP代码,通过借助n参数执行的SQL注入即可触发此漏洞。
CVSS Information
N/A
Vulnerability Type
N/A