Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in the store function in _phenotype/system/class/PhenoTypeDataObject.class.php in Phenotype CMS 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URI, as demonstrated by Gallery/gal_id/1/image1,1.html. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Phenotype CMS存储功能SQL注入漏洞
Vulnerability Description
Phenotype CMS是一个基于PHP/MySQL/Smarty实现的开源内容管理系统,具有易于编辑和简单高效等特性。 Phenotype CMS 3.0版本中的_phenotype/system/class/PhenoTypeDataObject.class.php中的存储功能中存在SQL注入漏洞。远程攻击者可以借助特制URI执行任意SQL命令。该漏洞已经通过Gallery/gal_id/1/image1,1.html文件得到证实。
CVSS Information
N/A
Vulnerability Type
N/A