Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-4894

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

chillyCMS 1.1.3版本的core/showsite.php中存在SQL注入漏洞。远程攻击者可借助name参数执行任意SQL命令。

AI Predicted 9.8 Difficulty: Easy EPSS 2.02% · P79

Public Exploits 1

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-4894

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
chillyCMS 'core/showsite.php'SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
chillyCMS 1.1.3版本的core/showsite.php中存在SQL注入漏洞。远程攻击者可借助name参数执行任意SQL命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-4894

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-4894

登录查看更多情报信息。

Vendor Advisories for CVE-2010-4894 (5)

Exploits & Public PoCs for CVE-2010-4894 (2)

Other References for CVE-2010-4894 (2)

Same Patch Batch · n/a · 2011-10-08 · 39 CVEs total

CVE-2011-0334 Novell GroupWise Internet Agent HTTP接口栈缓冲区溢出漏洞
CVE-2010-4914 PHP Classifieds tools/phpmailer/class.phpmailer.php PHP远程文件包含漏洞
CVE-2010-4915 ColdGen ColdBookmarks index.cfm SQL注入漏洞
CVE-2010-4916 ColdGen ColdUserGroup index.cfm 多个SQL注入漏洞
CVE-2010-4917 A-Blog sources/search.php SQL注入漏洞
CVE-2010-4918 Joomla! iJoomla Magazine组件 PHP远程文件包含漏洞
CVE-2010-4919 Micronetsoft RV Dealer Website detail.asp SQL注入漏洞
CVE-2010-4920 Micronetsoft Rental Property Management Website detail.asp SQL注入漏洞
CVE-2010-4921 DMXReady Polling Booth Manager inc_pollingboothmanager.asp SQL注入漏洞
CVE-2011-0333 Novell GroupWise Internet Agent ’TZNAME‘ 缓冲区溢出漏洞
CVE-2010-4913 ColdGen ColdUserGroup 搜索功能跨站脚本攻击漏洞
CVE-2011-1696 Novell Identity Manager 用户应用程序跨站脚本攻击漏洞
CVE-2011-2218 Novell GroupWise HP3 GWIA 未明拒绝服务漏洞
CVE-2011-2219 Novell GroupWise HP3 GWIA 未明拒绝服务漏洞
CVE-2011-2227 Novell Identity Manager用户应用程序跨站脚本攻击漏洞
CVE-2011-2661 Novell GroupWise WebAccess 多个跨站脚本攻击漏洞
CVE-2011-2662 Novell GroupWise ‘GroupWise Internet Agent ’ 数字错误漏洞
CVE-2011-2663 Novell GroupWise ‘GWIA‘ 缓冲区溢出漏洞
CVE-2011-3598 phpPgAdmin 多个跨站脚本攻击漏洞
CVE-2010-4904 Joomla! Aardvertiser组件SQL注入漏洞

Showing top 20 of 39 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-4894

No comments yet


Leave a comment