Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NewLife Blogger "nlb3" Cookie SQL注入漏洞
Vulnerability Description
NewLife Blogger是一个多用户博客系统,如LiveJournal.com。它使用的PHP,MySQL,以及方便的模板系统(ETS)。每个用户可以自定义,好友名单的外观,并设置为公共博客或受限博客博主或仅朋友可访问。 NewLife Blogger 3.0及其早期版本,以及可能的3.3.1版本中的system/nlb_user.class.php存在SQL注入漏洞,远程攻击者可以借助nlb3 cookie,执行任意SQL指令。
CVSS Information
N/A
Vulnerability Type
N/A