Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php with the id parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tilde CMS SQL注入漏洞
Vulnerability Description
Tilde CMS是一套网站内容管理系统(CMS)。 Tilde CMS 1.0.1版本中class.SystemAction.php文件存在SQL注入漏洞。远程攻击者可通过向带有‘id’参数的/actionphp/action.input.php发送POST请求利用该漏洞执行任意的SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A