Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Turnkey PHPLiveHelper onlinestatus_html.php SQL注入漏洞
Vulnerability Description
Turnkey PHP Live Helper是一套PHP编写的在线客户系统。 PHP Live Helper 2.0.1及其之前版本的版本中onlinestatus_html.php中存在SQL注入漏洞。 由于global.php中的get函数缺乏对用户输入的检查,远程攻击者利用onlinestatus_html.php的dep参数实现SQL注入,执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A