Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts. NOTE: the attack vector might involve _SERVER.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Jupiter CMS 多个SQL注入漏洞
Vulnerability Description
Jupiter CMS 1.1.5版本中存在多个SQL注入漏洞。远程攻击者可以借助Client-IP HTTP页眉和某些其他的HTTP页眉, 且这些页眉设置了在由index.php以及其他PHP脚本执行的SQL查询的ip自变量,执行任意SQL指令。 注意:该攻击向量可能包括_SERVER。
CVSS Information
N/A
Vulnerability Type
N/A