Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CMS Made Simple TinyMCE模块SQL注入漏洞
Vulnerability Description
CMS Made Simple是一个易于使用的内容管理系统用于具有简单、稳定内容的网站。使用PHP,MySQL和Smarty模板引擎开发。它具有:基于角色的权限管理系统,智能缓存机制(只有当需要时才会从数据库获取),基于向导的安装与更新机制,对系统资源占用少,还包含文件管理,新闻发布和RSS模块等。 CMS Made Simple 的TinyMCE 模块存在SQL注入漏洞。远程攻击者可以借助templateid参数,执行任意的SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A