Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZUUSE BEIMS ContractorWeb .NET SQL注入漏洞
Vulnerability Description
ZUUSE BEIMS ContractorWeb .NET是澳大利亚ZUUSE公司的一套基础设施管理软件。 ZUUSE BEIMS ContractorWeb .NET 5.18.0.0版本中的CWEBNET/WOSummary/List存在SQL注入漏洞。远程攻击者可借助多个参数利用该漏洞控制数据库或服务器,访问内部网络。(多个参数包括:‘tradestatus’、‘assetno’、‘assignto’、‘building’、‘domain’、‘jobtyp’、‘site’、‘trade’、‘woT
CVSS Information
N/A
Vulnerability Type
N/A