Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Jetbox CMS 多个SQL注入漏洞
Vulnerability Description
Jetbox CMS存在多个SQL注入漏洞,远程认证用户可以借助admin/cms/images.php的orderby参数和admin/cms/nav.php的editrecord操作中的nav_id参数,来执行任意的SQL指令。
CVSS Information
N/A
Vulnerability Type
N/A