Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Maxdev MDPro My_eGallery模块pid参数SQL注入漏洞
Vulnerability Description
MDPro是一款开放源码的内容管理系统。 MDPro的index.php文件没有正确地过滤对pid参数的输入参数,如果module设置为My_eGallery且do设置为showpic,远程攻击者就可以通过提交恶意请求执行SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A