Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
b2evolution 跨站请求伪造漏洞
Vulnerability Description
b2evolution是软件开发者Francois Planque所研发的一套基于PHP和MySQL的博客软件。 b2evolution 4.1.6及之前版本中的blogs/admin.php脚本存在跨站请求伪造漏洞。远程攻击者可借助‘show_statuses[]’参数利用该漏洞实施SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A