Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
bony2023 Discussion-Board main.php display_all_replies sql injection
Vulnerability Description
A vulnerability, which was classified as critical, has been found in bony2023 Discussion-Board. Affected by this issue is the function display_all_replies of the file functions/main.php. The manipulation of the argument str leads to sql injection. The patch is identified as 26439bc4c63632d63ba89ebc0f149b25a9010361. It is recommended to apply a patch to fix this issue. VDB-218378 is the identifier assigned to this vulnerability.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Discussion-Board SQL注入漏洞
Vulnerability Description
Discussion-Board是基于 PHP 的在线论坛。 Discussion-Board存在SQL注入漏洞,该漏洞源于文件 functions/main.php 的函数 display_all_replies,操作参数 str 导致 SQL注入。
CVSS Information
N/A
Vulnerability Type
N/A