Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cyclope Employee Surveillance Solution v6.x SQL Injection
Vulnerability Description
Cyclope Employee Surveillance Solution versions 6.x is vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to inject arbitrary SQL statements. This can be leveraged to write and execute a malicious PHP file on disk, resulting in remote code execution under the SYSTEM user context.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Cyclope Employee Surveillance Solution 安全漏洞
Vulnerability Description
Cyclope Employee Surveillance Solution是Cyclope公司的一个员工监控软件。 Cyclope Employee Surveillance Solution 6.x版本存在安全漏洞,该漏洞源于auth-login请求中username参数未清理,可能导致SQL注入和远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A