Valid tiny-erp 1.6及其之前版本中存在多个SQL注入漏洞,该漏洞源于对用户提供的数据在用于SQL查询之前没有经过充分的过滤。远程攻击者可利用该漏洞操控该应用程序,访问或者修改数据,或者借助作用于search的SearchField参数执行任意SQL命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2011-4671 | WordPress AdRotate插件SQL注入漏洞 | |
| CVE-2011-4673 | WordPress Jetpack插件SQL注入漏洞 | |
| CVE-2011-4674 | Zabbix ‘popup.php’SQL注入漏洞 | |
| CVE-2011-4669 | WordPress Users插件SQL注入漏洞 | |
| CVE-2011-4670 | vTiger CRM跨站脚本漏洞 | |
| CVE-2011-4033 | TeeChart活动控件远程拒绝服务漏洞 | |
| CVE-2011-4034 | TeeChart活动控件缓冲区溢出漏洞 | |
| CVE-2011-4035 | Vijeo Historian/CitectHistorian/CitectSCADA Reports跨站脚本漏洞 | |
| CVE-2011-4036 | Vijeo Historian/CitectHistorian/CitectSCADA Reports目录遍历漏洞 | |
| CVE-2011-4545 | Prestashop ‘admin/displayImage.php’代码注入漏洞 | |
| CVE-2011-4668 | IBM Tivoli Netcool/Reporter代码注入漏洞 |
No comments yet