Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7) c parameter to u5admin/editor.php; (8) typ parameter to u5admin/meta2.php; or (9) newname parameter to u5admin/rename2.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
u5CMS SQL注入漏洞
Vulnerability Description
u5CMS是一套基于PHP、MySQL和Apache的且用于中型网站、会议、审核流程、PayPal支付和在线调查的内容管理系统(CMS)。该系统支持所见即所得编辑器、创建调查表单和数据存储等。 u5CMS 3.9.4之前版本中存在SQL注入漏洞,该漏洞源于多个脚本(copy2.php,localize.php,metai.php,nc.php,new2.php,rename2.php)没有充分过滤‘name’参数;u5admin/editor.php脚本没有充分过滤‘c’参数;u5admin/meta2.
CVSS Information
N/A
Vulnerability Type
N/A