Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ActiveWebSoftwares Active Web Helpdesk 'default.asp' SQL注入漏洞
Vulnerability Description
Active Web Helpdesk是基于Web的咨询台管理工具。它工作原理是客户问题通过预置路径转往的适当人员,在回答了客户问题后(电子邮件发送给客户),把问题及回答结果直接保存到FAQ(常见问题)的数据库。 Active Web Helpdesk 2.0版本的default.aspx中存在SQL注入漏洞。远程攻击者可以借助Categoryid参数,执行任意SQL指令。
CVSS Information
N/A
Vulnerability Type
N/A