Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FrontAccounting SQL注入漏洞
Vulnerability Description
FrontAccounting(FA)是FrontAccounting公司的一套适用于中小型企业ERP供应链的财务软件。该软件包括采购订单、商品票据和账务分类与预算等模块。 FrontAccounting FA 2.4.5版本中的/attachments.php文件的‘filterType’参数存在SQL注入漏洞。远程攻击者可利用该漏洞获取该应用程序的整个数据库信息。
CVSS Information
N/A
Vulnerability Type
N/A