Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and ' (apostrophe) (%2500%2527).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Neocrome Seditio users.profile.inc.php SQL注入漏洞
Vulnerability Description
Neocrome Seditio 1.10及更早版本中的system/core/users/users.profile.inc.php存在SQL注入漏洞,远程认证用户可以通过一个传给users.php的以有效文件名开始的双url编码id参数来执行任意SQL命令,如通过在"default.gif"之后跟随一个编码NULL和' (撇号)(%2500%2527)。
CVSS Information
N/A
Vulnerability Type
N/A