Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BrewBlogger 'includes/authentication.inc.php' SQL 注入漏洞
Vulnerability Description
BrewBlogger(BB)是一款基于PHP的WEB应用程序。 BrewBlogger版本2.1.0.1的脚本includes/authentication.inc.php中的authenticateUser函数存在SQL注入漏洞。当magic_quotes_gpc失效时,远程攻击者可以通过脚本includes/logincheck.inc.php中的loginUsername参数执行任意的SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A