Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the PATH_INFO to /docushare/dsweb/ResultBackgroundJobMultiple/. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xerox DocuShare SQL注入漏洞
Vulnerability Description
Xerox DocuShare是美国施乐(Xerox)公司的一套基于Web的文档内容管理解决方案。该方案支持存储任何类型的文档、图像或视频,支持业务流程自动化、支持文档内容共享和协作等。 Xerox DocuShare中存在SQL注入漏洞,该漏洞源于/docushare/dsweb/ResultBackgroundJobMultiple/ URI没有充分过滤‘PATH_INFO’参数。远程攻击者可利用该漏洞执行任意SQL命令。以下版本受到影响:Xerox DocuShare 6.6.1,6.6.1:upd
CVSS Information
N/A
Vulnerability Type
N/A