Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, the (2) group_id parameter to group.php, the (3) status_id parameter to status.php, the (4) resolution_id parameter to resolution.php, the (5) severity_id parameter to severity.php, the (6) priority_id parameter to priority.php, the (7) os_id parameter to os.php, or the (8) site_id parameter to site.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Issuetracker phpBugTracker SQL注入漏洞
Vulnerability Description
Issuetracker phpBugTracker是一套基于Web的缺陷跟踪系统。该系统提供项目管理及缺陷跟踪服务等功能。 Issuetracker phpBugTracker 1.7.0之前的中存在SQL注入漏洞。远程攻击者可借助多个方法利用该漏洞执行任意的SQL命令。(多个方法包括:(1)向project.php文件发送‘id’参数、(2)向group.php文件发送‘group_id’参数、(3)向status.php文件发送‘status_id’参数、(4)向resolution.php文件发送
CVSS Information
N/A
Vulnerability Type
N/A