Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET["s"] variable from being unset. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in AJChat.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ming_han ajchat SQL注入漏洞
Vulnerability Description
AJchat 0.10版本中的directory.php允许远程攻击者可以借助一个具有与s参数的杂乱信息值相匹配的值的一个数字参数,防止相关的$_GET["s"]自变量未被安装,以绕过输入验证并执行SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A