Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xlinesoft PHPRunner 脚本UserView_list.php SQL注入漏洞
Vulnerability Description
PHPRunner是一款PHP网页制作工具,可以生成读写MySql数据库的PHP网页。 PHPRunner的UserView_list.php模块中没有正确地验证对SearchField参数所传送的输入便在SQL查询中使用,远程攻击者可以通过提交恶意查询请求执行SQL注入攻击,完全入侵数据库系统。
CVSS Information
N/A
Vulnerability Type
N/A