Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PunBB 'include/common.php' SQL注入漏洞
Vulnerability Description
当检查register_globals设置时,PunBB的include/common.php没有正确的处理被禁用的ini_get函数,存在SQL注入漏洞。远程攻击者可以注册global参数,进行SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A