Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Docebo autoDetectRegion函数 SQL注入漏洞
Vulnerability Description
Docebo 3.5.0.3及之前版本的oceboCore/lib/lib.regset.php中的autoDetectRegion函数存在SQL注入漏洞。远程攻击者可以借助Accept-Language HTTP头,执行任意的SQL指令。注意:攻击者可以使用INTO DUMPFILE指令,执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A