Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TornadoStore多个SQL注入漏洞
Vulnerability Description
TornadoStore 1.4.3以及早期版本存在多个SQL注入漏洞。远程攻击者可以借助(1) precios.php3中的marca参数或者(2) control/abm_list.php3中的delivery_courier操作中的where参数执行任意的SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A