Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL commands via the login parameter in a (1) send_pw_by_email or (2) generate_new_password action in sources/main.queries.php; iDisplayStart parameter to (3) datatable.logs.php or (4) a file in source/datatable/; or iDisplayLength parameter to (5) datatable.logs.php or (6) a file in source/datatable/; or allow remote authenticated users to execute arbitrary SQL commands via a sSortDir_ parameter to (7) datatable.logs.php or (8) a file in source/datatable/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TeamPass SQL注入漏洞
Vulnerability Description
TeamPass是一款专用于Apache、MySQL和PHP中的密码管理器。 TeamPass 2.1.20 beta及之前版本中存在SQL注入漏洞,该漏洞源于程序在执行send_pw_by_email或generate_new_password操作时,sources/main.queries.php脚本未充分过滤‘login’参数;datatable.logs.php脚本和‘source/datatable/’URI下的多个脚本文件未充分过滤‘iDisplayStart’参数、‘ iDisplayLen
CVSS Information
N/A
Vulnerability Type
N/A