Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to license/records.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Raritan Power IQ SQL注入漏洞
Vulnerability Description
Raritan Power IQ是美国力登(Raritan)公司的一套数据中心能源管理软件。该软件可对数据中心或IT实验室中的服务器提供集中电源、电流控制,热度与能源分析、创建趋势和状态报告等功能。 Raritan Power IQ 4.1.0版本和4.2.1版本中存在SQL注入漏洞,该漏洞源于license/records URL没有充分过滤‘sort’和‘dir’参数。远程攻击者可利用该漏洞执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A