Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated users with permission to maintain acronyms to execute arbitrary SQL commands via the id parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TYPO3 Akronymmanager扩展SQL注入漏洞
Vulnerability Description
TYPO3是瑞士TYPO3协会维护的一套免费开源的内容管理系统(框架)(CMS/CMF)。Akronymmanager(也称SB Folderdownload)是其中的一个用于显示文件下载链接地址的扩展插件。 TYPO3 Akronymmanager扩展7.0.0之前版本的mod1/index.php脚本中存在SQL注入漏洞。远程攻击者可借助‘id’参数利用该漏洞以‘maintain acronyms’权限执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A